TL;DR
Get privacy and security gear delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
Politiken reports that at least three Pays ApS accounts involved in the breach of Denmark’s CPR register used the password “123456,” including an administrator account. The reported intrusion lasted 21 days and 17 hours and involved information linked to around 8.8 million CPR numbers; the precise data accessed and the full impact on individuals have not been established in the source material.
At least three Pays ApS accounts, including an administrator account, reportedly used the password “123456” when hackers accessed Denmark’s central civil registration system, Politiken reported. The breach involved information linked to around 8.8 million CPR numbers, but the available account does not specify exactly which records were retrieved or how many people were affected.
Politiken said it reviewed data that the hacker allegedly used to gain access and found that at least three user accounts at Pays ApS used the widely known password. The company is based in Odense and provides IT services. Denmark’s Central Business Register listed the company as having two employees as of July 2026; the source does not explain how that figure relates to the number of accounts identified.
Pays managing director and owner Sophie Laursen confirmed to TV 2 that the company’s authorized access to the CPR system had been abused. The reported access began on September 10 and continued for 21 days and 17 hours. The source does not specify when the access ended or give a calendar date for that point.
An anonymous person who told Politiken they carried out the attack said they initially used a leaked password belonging to a former employee of a small Danish company. The person claimed to have created two programs to retrieve CPR information and store it externally, and told the newspaper there were no plans to sell or publish the material. Those details are the alleged attacker’s account, not independently established findings in the supplied reporting.
The Risks of Weak Access Controls
The report matters because the CPR system holds personal information about people who live in or have previously been registered in Denmark. Information connected to around 8.8 million CPR numbers makes the incident a serious privacy concern, though that figure does not establish how many records were actually viewed, copied or otherwise exposed.
Companies and associations may receive authorized CPR access when they have a legitimate need, such as confirming addresses for customers or members. The incident highlights the risk that access granted for a limited business purpose can be misused if account credentials are exposed or inadequately protected. The reported use of “123456” on multiple accounts adds to concerns about password practices, but the source does not establish that this password alone enabled the breach.
For people whose information may be involved, the central practical question is what data was accessed and whether it was retained or shared. The source material does not confirm that the information has been published, sold or used for fraud. The alleged hacker’s statement that there were no plans to distribute it is not a guarantee about what happened to the data.
password manager for secure password storage
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Pays Had CPR Access
Denmark’s CPR system is the country’s central civil registration database. It contains personal information on people living in Denmark and those previously registered there. Access is not limited to public authorities: private companies and associations can be granted access where they have a legitimate need, including obtaining address details about customers or members.
Pays confirmed that the compromised access was its legal access to search the register. That confirmation establishes the company’s connection to the incident, while the precise technical route into its systems remains less clear. The anonymous person who spoke to Politiken alleged that a former employee’s leaked password was used at the outset, followed by programs that retrieved and stored information. This sequence has not been presented in the source as an independently verified technical investigation.
Aarhus University cybersecurity professor Jens Myrup Pedersen commented on the reported passwords to Politiken. He called the company’s password security “hopeless” and said “123456” would be among the first passwords an attacker might try. His assessment concerns the reported password practice; it does not, by itself, establish the full cause or scope of the intrusion.
“There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.”
— Jens Myrup Pedersen, professor at Aarhus University’s Department of Electrical and Computer Engineering, speaking to Politiken
The Data Exposure Still Unclear
The reporting does not establish exactly which personal details were accessed, how many individual records were retrieved, or whether every CPR number linked to the reported 8.8 million was affected. The number refers to CPR numbers associated with the breach, not a confirmed count of people whose data was copied or misused.
It also remains unclear from the supplied material how investigators verified the anonymous person’s account, whether the reported programs and stored data have been recovered, and whether the data was shared with anyone else. The alleged attacker’s stated lack of plans to sell or publish it remains an unverified claim. No findings from a completed investigation, or details of any response measures, are included in the report.
Investigation and Data Impact
The next developments to watch are findings that clarify how the credentials were obtained, what information was accessed and whether it was copied or distributed. Further statements from Pays or relevant authorities could establish the incident’s technical scope and what steps are being taken to secure access to the register.
The source material does not provide a timetable for an investigation, a public notification process or specific guidance for people concerned about their records. Until more details are released, the reported account-password findings and the attacker’s description should be treated as distinct from independently verified conclusions about the breach.
Key Questions
What happened in the Danish CPR breach?
Pays ApS confirmed that its authorized access to search Denmark’s CPR register was abused. Politiken reported that at least three Pays accounts, including an administrator account, used the password “123456.”
How many CPR numbers were linked to the breach?
The report says information linked to around 8.8 million CPR numbers was exposed. It does not establish how many records were actually retrieved or how many people’s data was copied.
How long did the reported access last?
The access reportedly began on September 10 and lasted 21 days and 17 hours. The supplied report does not specify the date on which that period ended.
Has the data been published or sold?
That is not confirmed. An anonymous person who claimed responsibility told Politiken there were no plans to sell or publish the information, but the statement has not been independently verified in the source material.
What information was taken?
The source describes information linked to CPR numbers but does not specify which personal details were accessed, how many records were retrieved, or whether the data was shared or misused.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
