The Spectrum Dispatch News

technology

Danish CPR Breach Used '123456' Password on Admin Account

Hackers accessed Denmark's civil registration database for 21 days through a Funen-based IT firm using one of the internet's most common passwords.

Danish CPR Breach Used '123456' Password on Admin Account

At least three user accounts at Pays ApS, a Funen-based IT company, used the password “123456” when hackers breached Denmark’s CPR register, according to Politiken. One of the compromised accounts was the company’s administrator account.

Danish CPR Breach Used ‘123456’ Password on Admin Account

The breach exposed information linked to approximately 8.8 million CPR numbers. Denmark’s CPR system is the country’s central civil registration database containing personal information on people living or previously registered in Denmark.

Jens Myrup Pedersen, a professor at Aarhus University’s Department of Electrical and Computer Engineering, criticized the company’s security practices. “There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords,” he told Politiken. He added that he found it difficult to imagine worse security measures.

Pays ApS, based in Odense, confirmed to TV 2 that it was the compromised company. Managing director and owner Sophie Laursen stated in an email: “We can confirm that we are the company that has been subjected to an attack where our legal access to search for information in the CPR system has been abused.”

According to an anonymous hacker who contacted Politiken, gaining access was not particularly difficult. The attacker initially obtained access using a leaked password belonging to a former employee of a small Danish company. The hacker then allegedly created two computer programs to retrieve information from the CPR system and store it externally.

The hacker had access to the CPR register for 21 days and 17 hours, starting September 10. The hacker told Politiken there were no plans to sell or publish the information.

Private companies and associations can receive access to CPR register information when they have a legitimate need, such as obtaining address information about customers or members. According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

Key facts

  • At least three accounts at Pays ApS used the password ‘123456’, including an administrator account
  • The breach exposed information linked to approximately 8.8 million CPR numbers
  • The hacker had access for 21 days and 17 hours starting September 10
  • Access was initially obtained using a leaked password from a former employee of another company
  • Pays ApS had two employees as of July 2026

Sources

← All posts