Simple Password Used to Access Danish CPR Registry
A hacker claims to have accessed Denmark's central person register using a simple password.
2026年10月9日
/ DANGDI / DANGDI / DANGDI /A hacker claims to have accessed Denmark's CPR registry using a simple password. The breach highlights major security gaps in Denmark's central personal identification system. Every resident in Denmark relies on a CPR number for healthcare, banking, and public services.
The anonymous cybercriminal spoke to the Danish newspaper Politiken. He said he used the password '123456' to enter the register. The password belonged to a former employee of a small Danish company. That company had authorized access to the CPR database.
The password was previously exposed in an earlier data leak. The hacker wrote two computer programs to scrape and save CPR records. Cybersecurity expert Emil Hørning from Defend Denmark reviewed the stolen data list. He and other experts confirmed the hack appears genuine.
The hacker stated he has no plans to sell or leak the stolen CPR numbers. He expressed shock at the weak security surrounding Denmark's central registry. Private companies can request CPR access to verify customer addresses.
Digitalisation minister Christina Egelund acknowledged that security was not good enough. She confirmed that officials have introduced new protective measures. The government has also ordered a full security analysis of the system.
Source: The Local Denmark


