Technology

Denmark's CPR Breach Came Down to '123456' and Old Accounts

Martin HollowayPublished 22m ago3 min readBased on 7 sources
Reading level
Denmark's CPR Breach Came Down to '123456' and Old Accounts
Photo by Jefferson Santos on Unsplash

At least three user accounts at Funen-based IT company Pays used the password "123456" when attackers gained access to Denmark's CPR register. The detail was reported on 10 October 2026. Copenhagen Post

That password stood in front of a national identity system. Attackers obtained CPR data by misusing a private Danish company's legitimate access to search Denmark's Central Person Register. Help Net Security

Unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people through that private company. The Hacker News

The most precise count comes from the person claiming responsibility. A hacker claiming to be behind the breach shared 8.7 million ID records with the newspaper Politiken, and told Politiken that 8,749,975 CPR records were protected by the password "123456". Politiken

The hacker's own account of the method is narrow. The hacker says they logged in with a former employee's leaked password "123456", a claim that had not been officially confirmed. CSIS

The broader context here helps explain what happened. The disclosures describe a compromise of delegated trust, not a direct break-in to the register itself. The register was queried through authorized channels. The failure was in who held those channels and how they were guarded.

To put that architecture in practical terms, central registries are built for broad lookup by vetted intermediaries, meaning approved organizations allowed to search the system. Municipalities, healthcare providers, financial firms and IT processors all need automated search. That design concentrates risk in identity controls at the edge, where password policy, rotation after offboarding, secure storage of passwords, and session monitoring become the perimeter.

For enterprise and public-sector architects, the Pays detail shifts attention from bulk exfiltration to credential hygiene and lifecycle management, meaning how passwords are created, checked and retired. Three accounts sharing the same weak secret suggests uniqueness was not enforced and passwords were not checked against known leaks. A former employee credential still working suggests deprovisioning, the removal of access when staff leave, did not propagate. Neither point has been officially confirmed as the definitive root cause. Both are questions a post-incident review will have to answer with logs, not assertions.

In my view, worth flagging is how little sophistication this attack required if the hacker's account holds. No zero-day, a previously unknown software flaw, was used. No custom malware was described. The attackers used valid credentials and legitimate query interfaces at scale. That pattern punishes detection tuned for malicious files or network exploits. It rewards query-rate anomaly detection, alerts for logins from unlikely locations, baselining of service accounts to spot unusual behavior, and immutable audit trails, tamper-proof logs, for every lookup against person registers. For tech-literate organizations, the lesson is not new, but it is sharp. The controls that matter here are boring and operational.

Looking further ahead, recovery will be procedural and slow. CPR numbers do not rotate like passwords. Names and addresses change slowly. Once that triplet leaves a controlled system, containment means monitoring for misuse, tightening downstream authentication that relied on those identifiers, and rebuilding trust in the access model. The work ahead will involve credential resets, access recertification, least-privilege scoping for bulk search, meaning strictly limiting who can run large searches, and clearer contractual liability between registry operators and private intermediaries.

On a personal note, my kids grew up typing passwords into school portals and, later, password managers. The difference was never explained to them as cryptography. It was explained as house keys. You do not leave the same key under three doormats and you change the locks when someone moves out. Denmark now has to change a great many locks at once.