Simple password used in massive Danish CPR data leak
Hackers accessed 8.8 million CPR records after a firm used 123456 as an admin password.
2026年10月10日
/ DANGDI / DANGDI / DANGDI /A massive breach exposed personal data linked to 8.8 million Danish CPR numbers. Hackers accessed Denmark's civil register through a company using the password "123456". This compromised account belonged to an administrator at Funen-based IT company Pays ApS. Politiken first reported the security failure.
The hacker maintained unauthorized access to CPR data for nearly 22 days starting September 10. They initially used a leaked password from a former employee of another small Danish firm. The hacker built two custom programs to download and store the data externally. Aarhus University professor Jens Myrup Pedersen called the company's security hopeless.
Pays ApS managing director Sophie Laursen confirmed the attack to TV 2. The Odense firm had only two employees as of July 2026. Private firms in Denmark can access CPR data to verify customer address details. The hacker told Politiken that they do not plan to sell or publish the leaked records. CPH Post covered the report.
Source: The Copenhagen Post


