123456' password used in Danish CPR data breach
The breach involved misuse of Pays ApS’s lawful access to Denmark’s CPR register. Hackers entered through compromised company accounts and were able to search the government database. The incident matters because the register contains personal information about people living or previously registered in Denmark. According to the anonymous hacker, access began with a leaked password belonging to a former employee of a small Danish company. The hacker then allegedly created two computer programs. Those programs retrieved information from the CPR system and stored it outside the system. Pays confirmed that its access had been compromised. The hacker had access from 10 September for 21 days and 17 hours. Information linked to around 8.8 million CPR numbers was exposed. The hacker claimed there were no plans to sell or publish the information, but the breach showed how compromised accounts could be used to automate large-scale searches.
What happened when hackers used compromised Pays accounts to access Denmark’s CPR register?
The breach involved misuse of Pays ApS’s lawful access to Denmark’s CPR register. Hackers entered through compromised company accounts and were able to search the government database. The incident matters because the register contains personal information about people living or previously registered in Denmark.
According to the anonymous hacker, access began with a leaked password belonging to a former employee of a small Danish company. The hacker then allegedly created two computer programs. Those programs retrieved information from the CPR system and stored it outside the system. Pays confirmed that its access had been compromised.
The hacker had access from 10 September for 21 days and 17 hours. Information linked to around 8.8 million CPR numbers was exposed. The hacker claimed there were no plans to sell or publish the information, but the breach showed how compromised accounts could be used to automate large-scale searches.
What is Denmark’s CPR register, and what kind of personal information does it contain?
The CPR register is Denmark’s central civil registration database. It is a government-held system containing personal information connected with people who live, or previously lived, in Denmark. That makes it a major source of population records and explains why unauthorized access is serious.
The article gives one practical example of its use. Private companies and associations may receive access when they have a legitimate need, such as obtaining address information about customers or members. Pays had lawful access to search the system, but that access was allegedly abused after company accounts were compromised.
The reported breach involved information linked to around 8.8 million CPR numbers. The article does not list every category of information in the register. It establishes that the database covers people currently or formerly registered in Denmark and includes personal information. Its broad population coverage made the incident especially significant.
How many CPR numbers were linked to information exposed in the breach?
The breach exposed information linked to around 8.8 million CPR numbers. A CPR number is part of Denmark’s civil registration system, so this figure indicates that the incident involved records connected to a very large share of people registered in the country. The scale is the central reason the breach drew national attention.
The access did not come from a government employee account, according to the reported account. Pays ApS, a small IT company based in Odense, had legal permission to search the CPR system. After accounts were compromised, the hacker allegedly used computer programs to retrieve information and store it externally. The company had two employees as of July 2026.
The article does not say that every record was copied in full, nor does it identify specific people affected. It reports that information linked to around 8.8 million CPR numbers was exposed. The figure highlights how one compromised access route can have consequences across a nationwide register.
How did using the password “123456,” including on an administrator account, make the company’s systems vulnerable?
Using “123456” made the accounts vulnerable because it is one of the first passwords an attacker would try. Jens Myrup Pedersen, a professor at Aarhus University, described the company’s password security as “hopeless.” The weakness was especially serious because one of the accounts was an administrator account.
An administrator account can have broad authority within a company’s systems. In this case, at least three Pays user accounts reportedly used the same extremely common password. The article also reports that access was initially obtained through a leaked password belonging to a former employee. Together, these details show how weak or exposed credentials can become an entry point.
The reported result was access to Pays’s legal connection with the CPR register. The hacker allegedly used programs to retrieve information for 21 days and 17 hours. The article does not describe every technical control in place, but the professor said the security was effectively an “open door.”
How did the hacker reportedly use access to retrieve and store information from the CPR system?
The reported method turned access into a system for collecting information. After entering the CPR system, the hacker allegedly used two computer programs to retrieve records and save them externally. This matters because automated tools can gather information more consistently and at a much larger scale than manual searches.
The anonymous hacker told Politiken that access was initially obtained through a leaked password belonging to a former employee of a small Danish company. The hacker then allegedly built the programs to handle retrieval and storage. The article does not explain precisely how the programs queried the system or where the external storage was located.
The hacker had access from 10 September for 21 days and 17 hours. Information linked to around 8.8 million CPR numbers was exposed. The hacker claimed there were no plans to sell or publish the information, but the external storage meant the information had been copied beyond the CPR system.
What can happen to people when sensitive civil-registration information is accessed or copied without authorization?
When civil-registration information is accessed or copied without permission, people can lose control over sensitive personal details. Such information may be used for privacy invasion, unwanted contact, impersonation, or fraud. These are general risks of unauthorized personal-data access; the article does not report that any particular harm occurred to individuals in this case.
The reported breach involved information linked to around 8.8 million CPR numbers. The hacker allegedly created programs that retrieved information from the CPR system and stored it externally. Once data is copied outside the original system, the organization controlling the register may have less ability to monitor or limit its use.
The article says the hacker claimed there were no plans to sell or publish the information. It does not identify what specific personal details were copied or describe consequences for named residents. The incident nevertheless shows why access to a population register must be tightly controlled, monitored, and protected from compromised accounts.
Why are private companies allowed to access a government population register at all, and what principle is supposed to limit that access?
Private companies and associations are allowed to use Denmark’s CPR register because some legitimate activities require current address information. The article gives customers and members as examples. Access is therefore not presented as open-ended; it is granted when an organization can show a genuine reason to search the register.
Pays ApS had legal access to search the CPR system. The reported problem was that hackers abused this access after compromising company accounts. They allegedly used programs to retrieve information and store it outside the CPR system. The incident shows the difference between authorized access for a defined purpose and unauthorized use of that access.
The limiting principle stated in the article is legitimate need. Pays confirmed that its legal access had been compromised, while the hacker reportedly reached information linked to around 8.8 million CPR numbers. The article does not describe additional rules or enforcement measures, but the breach highlights why access permissions must remain tied to their stated purpose.
This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.
Read more in the JupiteX app
Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.
Or read more news on the web