`123456' Password Used In Danish CPR Data Breach
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Before you orderOffer from Amazon

Get privacy and security gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Politiken reports that at least three accounts at Pays ApS, including an administrator account, used the password “123456” when the company’s authorized access to Denmark’s CPR register was abused. The breach involved information linked to about 8.8 million CPR numbers; the exact data retrieved and the identities of affected people have not been detailed in the supplied reporting.

At least three accounts at Pays ApS, including an administrator account, reportedly used the password “123456” when the company’s access to Denmark’s central civil register was abused, according to Politiken. The breach involved information linked to about 8.8 million CPR numbers, though the precise records accessed have not been specified in the reporting provided; see the Denmark data breach report.

Politiken reported that it reviewed data allegedly used by the hacker to gain access to the CPR system and found that at least three Pays user accounts had the same widely used password. The report identified one of them as an administrator account. Pays, an IT company based in Odense, confirmed to TV 2 that it was the company whose authorized access had been compromised.

Pays managing director and owner Sophie Laursen said the company’s legal access to search the register had been abused in an attack. The reported access began on September 10 and lasted 21 days and 17 hours. The source material does not state when the intrusion was detected or when access was shut down.

An anonymous person who told Politiken they carried out the attack claimed they first used a leaked password belonging to a former employee of a small Danish company. The person also said they created two programs to retrieve register information and store it elsewhere. These details are the hacker’s account of events, not independently established findings in the material provided.

At a glance
updateWhen: Reported October 10, 2026; the reported…
The developmentA report by Politiken says three Pays ApS accounts, including an administrator account, used “123456” during an intrusion that accessed Denmark’s CPR register.

Exposure Across Denmark’s Civil Register

The CPR register is Denmark’s central civil registration database, holding personal information about people who live in or have previously been registered in the country. Information associated with around 8.8 million CPR numbers was involved in the breach, a scale that makes the incident relevant well beyond Pays and its customers.

The report does not establish that every person linked to those numbers had information retrieved, or that every type of personal data in the register was exposed. Still, misuse of a company’s authorized connection to a government register raises questions about how access credentials are protected, monitored and limited. If information was copied outside the system, it could also be difficult to determine whether it has been deleted or shared.

Jens Myrup Pedersen, a professor in Aarhus University’s Department of Electrical and Computer Engineering, criticized the reported password practices. His comments are an expert assessment of the password security described by Politiken; they do not by themselves establish the full technical cause or scope of the breach.

Amazon

password manager for secure password storage

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Pays Could Search the Register

Denmark allows some private companies and associations to access CPR information when they have a legitimate need. One example is obtaining address information about customers or members. Pays had such legal search access, according to Laursen’s statement to TV 2; the company said that this access was abused in the attack.

The distinction between authorized access and its alleged misuse matters: the reporting describes an attacker gaining entry through credentials and then using the connection to the register, rather than claiming that the CPR system itself was publicly accessible. Denmark’s Central Business Register listed Pays as having two employees in July 2026. That figure provides company-size context but does not establish how its systems were managed or who had access to the accounts.

““There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.””

— Jens Myrup Pedersen, professor at Aarhus University, speaking to Politiken

Amazon

multi-factor authentication device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Scope and Data Use Still Unclear

The reporting does not say precisely which records were retrieved, how many individuals’ information was copied, or whether sensitive details beyond information linked to CPR numbers were involved. It also does not describe the contents of the data reviewed by Politiken in enough detail to determine the full exposure.

The anonymous hacker told Politiken there were no plans to sell or publish the information. That assurance comes from the person claiming responsibility and does not confirm that the information remains private, has been deleted, or has not been passed to anyone else. The supplied reports also do not include findings from law enforcement, a regulator or an independent technical investigation about the attack’s route, the accounts involved, or any steps taken to secure them.

Amazon

VPN for privacy protection

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Investigation and Access Controls

The next developments to watch are any findings from authorities or technical investigators on how the credentials were obtained, what information was queried or copied, and whether it has been contained. Further detail from Pays or the public bodies responsible for CPR access could clarify whether the reported passwords were active during the intrusion and what safeguards have since changed.

The supplied reporting does not announce a timetable for an investigation, a notification process for people whose information may be affected, or changes to Pays’ access. Until those details are provided, the confirmed position is that Pays acknowledged an attack abusing its register access, while the account of the attacker’s methods and the precise consequences remain incomplete.

Amazon

laptop security lock

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What happened in the Danish CPR breach?

Pays ApS confirmed that an attack abused its authorized access to search Denmark’s CPR register. Politiken reported that at least three company accounts, including an administrator account, used the password “123456”.

How many CPR numbers were involved?

The breach was reported to involve information linked to about 8.8 million CPR numbers. The available reporting does not say how many individual records were actually retrieved.

When did the reported access take place?

The reported access began on September 10 and lasted 21 days and 17 hours. The supplied material does not specify when the intrusion was discovered or stopped.

Was the stolen information published or sold?

An anonymous person claiming responsibility told Politiken there were no plans to sell or publish the information. That statement has not established whether data was copied, shared, deleted or otherwise used.

What remains unknown about the incident?

The exact records accessed, the number of people affected, the full method of entry and the results of any official investigation have not been detailed in the supplied reporting.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

RFC 9851: TLS 1.2 Is In Feature Freeze

RFC 9851 officially states that TLS 1.2 is in feature freeze, signaling no further major updates. This impacts security protocols and future development.

OpenAI’s Accidental Attack Against Hugging Face Is Science Fiction That Happened

OpenAI’s internal testing mishap caused an unintended security breach targeting Hugging Face, highlighting risks in AI model evaluation.

CVE-2026-58644: Microsoft SharePoint Deserialization Of Untrusted Data Vulnerability Actively Exploited (CISA KEV)

A critical vulnerability in Microsoft SharePoint, CVE-2026-58644, is actively exploited, allowing remote code execution via deserialization of untrusted data.

FBI Arrests CIA Official with $40M in Gold Bars in His Home

A senior CIA official was arrested after authorities found over $40 million worth of gold bars and foreign currency at his home, raising questions about his conduct.