AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Before you orderOffer from Amazon

Get privacy and security gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Politiken reports that at least three Pays ApS accounts involved in the breach of Denmark’s CPR register used the password “123456,” including an administrator account. The reported intrusion lasted 21 days and 17 hours and involved information linked to around 8.8 million CPR numbers; the precise data accessed and the full impact on individuals have not been established in the source material.

At least three Pays ApS accounts, including an administrator account, reportedly used the password “123456” when hackers accessed Denmark’s central civil registration system, Politiken reported. The breach involved information linked to around 8.8 million CPR numbers, but the available account does not specify exactly which records were retrieved or how many people were affected.

Politiken said it reviewed data that the hacker allegedly used to gain access and found that at least three user accounts at Pays ApS used the widely known password. The company is based in Odense and provides IT services. Denmark’s Central Business Register listed the company as having two employees as of July 2026; the source does not explain how that figure relates to the number of accounts identified.

Pays managing director and owner Sophie Laursen confirmed to TV 2 that the company’s authorized access to the CPR system had been abused. The reported access began on September 10 and continued for 21 days and 17 hours. The source does not specify when the access ended or give a calendar date for that point.

An anonymous person who told Politiken they carried out the attack said they initially used a leaked password belonging to a former employee of a small Danish company. The person claimed to have created two programs to retrieve CPR information and store it externally, and told the newspaper there were no plans to sell or publish the material. Those details are the alleged attacker’s account, not independently established findings in the supplied reporting.

At a glance
updateWhen: Reported October 10, 2026; the access p…
The developmentPolitiken reported that three accounts at Pays ApS, the company that confirmed its CPR access was abused, used the password “123456,” including an administrator account.

The Risks of Weak Access Controls

The report matters because the CPR system holds personal information about people who live in or have previously been registered in Denmark. Information connected to around 8.8 million CPR numbers makes the incident a serious privacy concern, though that figure does not establish how many records were actually viewed, copied or otherwise exposed.

Companies and associations may receive authorized CPR access when they have a legitimate need, such as confirming addresses for customers or members. The incident highlights the risk that access granted for a limited business purpose can be misused if account credentials are exposed or inadequately protected. The reported use of “123456” on multiple accounts adds to concerns about password practices, but the source does not establish that this password alone enabled the breach.

For people whose information may be involved, the central practical question is what data was accessed and whether it was retained or shared. The source material does not confirm that the information has been published, sold or used for fraud. The alleged hacker’s statement that there were no plans to distribute it is not a guarantee about what happened to the data.

password manager for secure password storage

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Pays Had CPR Access

Denmark’s CPR system is the country’s central civil registration database. It contains personal information on people living in Denmark and those previously registered there. Access is not limited to public authorities: private companies and associations can be granted access where they have a legitimate need, including obtaining address details about customers or members.

Pays confirmed that the compromised access was its legal access to search the register. That confirmation establishes the company’s connection to the incident, while the precise technical route into its systems remains less clear. The anonymous person who spoke to Politiken alleged that a former employee’s leaked password was used at the outset, followed by programs that retrieved and stored information. This sequence has not been presented in the source as an independently verified technical investigation.

Aarhus University cybersecurity professor Jens Myrup Pedersen commented on the reported passwords to Politiken. He called the company’s password security “hopeless” and said “123456” would be among the first passwords an attacker might try. His assessment concerns the reported password practice; it does not, by itself, establish the full cause or scope of the intrusion.

“There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.”

— Jens Myrup Pedersen, professor at Aarhus University’s Department of Electrical and Computer Engineering, speaking to Politiken

The Data Exposure Still Unclear

The reporting does not establish exactly which personal details were accessed, how many individual records were retrieved, or whether every CPR number linked to the reported 8.8 million was affected. The number refers to CPR numbers associated with the breach, not a confirmed count of people whose data was copied or misused.

It also remains unclear from the supplied material how investigators verified the anonymous person’s account, whether the reported programs and stored data have been recovered, and whether the data was shared with anyone else. The alleged attacker’s stated lack of plans to sell or publish it remains an unverified claim. No findings from a completed investigation, or details of any response measures, are included in the report.

Investigation and Data Impact

The next developments to watch are findings that clarify how the credentials were obtained, what information was accessed and whether it was copied or distributed. Further statements from Pays or relevant authorities could establish the incident’s technical scope and what steps are being taken to secure access to the register.

The source material does not provide a timetable for an investigation, a public notification process or specific guidance for people concerned about their records. Until more details are released, the reported account-password findings and the attacker’s description should be treated as distinct from independently verified conclusions about the breach.

Key Questions

What happened in the Danish CPR breach?

Pays ApS confirmed that its authorized access to search Denmark’s CPR register was abused. Politiken reported that at least three Pays accounts, including an administrator account, used the password “123456.”

How many CPR numbers were linked to the breach?

The report says information linked to around 8.8 million CPR numbers was exposed. It does not establish how many records were actually retrieved or how many people’s data was copied.

How long did the reported access last?

The access reportedly began on September 10 and lasted 21 days and 17 hours. The supplied report does not specify the date on which that period ended.

Has the data been published or sold?

That is not confirmed. An anonymous person who claimed responsibility told Politiken there were no plans to sell or publish the information, but the statement has not been independently verified in the source material.

What information was taken?

The source describes information linked to CPR numbers but does not specify which personal details were accessed, how many records were retrieved, or whether the data was shared or misused.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

CVE-2026-0770: Langflow Inclusion Of Functionality From Untrusted Control Sphere Vulnerability Actively Exploited (CISA KEV)

A vulnerability in Langflow, CVE-2026-0770, enables remote attackers to execute arbitrary code by including functionality from an untrusted control sphere, actively exploited.

Mozilla to UK regulators: VPNs are essential privacy and security tools

Mozilla urges UK regulators to preserve VPN access, emphasizing their role in online privacy and security, amid discussions on digital safety measures.

Keyv And Friends Compromised In Active Shai-Hulud Supply Chain Attack

Hackers compromised Keyv and associated entities in an ongoing supply chain attack targeting the Shai-Hulud network, raising security concerns.

SeL4 Security Proofs Now Complete On AArch64

The formal security proofs for the seL4 microkernel on the AArch64 platform are now finalized, marking a significant milestone in verified systems security.