TL;DR
Get privacy and security gear delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
At least three accounts at Pays ApS reportedly used the password ‘123456’ when the company’s access to Denmark’s CPR register was abused, Politiken reported. The breach involved information linked to around 8.8 million CPR numbers; the full extent of data retrieval and potential exposure remains unclear.
At least three accounts at Pays ApS reportedly used the password ‘123456’ when the company’s access to Denmark’s central civil register was abused, Politiken reported. One account was an administrator account. The breach involved information linked to around 8.8 million CPR numbers, making the reported password practices a concern in a case affecting a database holding personal information on people living or previously registered in Denmark.
Politiken said it reviewed data that the hacker allegedly used to gain access to the CPR system. The report said the hacker had access through Pays from September 10 for a total of 21 days and 17 hours. The figure of 8.8 million refers to CPR numbers linked to information involved in the breach; the available reporting does not establish how many records were actually retrieved or what personal details were accessed for each person.
Pays, an IT company based in Odense, confirmed to TV 2 that it was the company whose authorized access had been compromised. Managing director and owner Sophie Laursen said in an email that the company had been attacked and its “legal access to search for information in the CPR system” had been abused. Her statement confirms the company’s involvement in the incident, but does not independently confirm the password details reported by Politiken.
An anonymous person who told Politiken they carried out the attack said access was initially gained using a leaked password belonging to a former employee of a small Danish company. The person claimed to have then made two programs to retrieve information from the register and store it outside the system. Those details come from the alleged hacker and have not been independently established in the material provided. The hacker also told Politiken there were no plans to sell or publish the information.
Why Weak Account Security Matters
The reported use of ‘123456’ on multiple accounts, including an administrator account, raises questions about how Pays protected its authorized connection to a highly sensitive public register. Jens Myrup Pedersen, a professor at Aarhus University, told Politiken that such a common password would be among the first guesses an intruder might try. His assessment concerns the reported password practices; it does not, on its own, establish the complete sequence of events or the security controls in place.
The CPR register contains personal information about people who live in Denmark or have been registered there in the past. If information was copied and retained outside the system, it could create risks for affected people beyond the period when the attacker had access. However, the reporting supplied does not say what specific data was taken, whether it has been shared, or whether anyone has experienced harm as a result.
The case also highlights the risks that can arise when private organizations are given access to government-held information. Authorized access can serve legitimate purposes, but the reported incident shows why account security and oversight matter: a breach through a contractor or service provider can involve information concerning millions of people.
hardware security keys for password protection
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Denmark’s CPR is the country’s central civil registration database. According to the report, private companies and associations may receive access when they have a legitimate need, such as obtaining address information about customers or members. Pays had authorized access to search the register; Laursen’s statement to TV 2 says that access was abused in an attack.
According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026. That detail describes the company’s listed size at that date; it does not establish who was responsible for security decisions or how the incident occurred. Politiken’s account of the alleged intruder’s route, including use of a former employee’s leaked password, remains an attributed claim.
The reported access period was 21 days and 17 hours, beginning September 10. The report does not specify in the supplied material when the access ended or when the breach was discovered. Pays’s confirmation to TV 2 establishes that its CPR access was compromised, while the additional account of how the attacker entered and extracted information relies on Politiken’s reporting and the anonymous person’s claims.
““There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.””
— Jens Myrup Pedersen, professor at Aarhus University’s Department of Electrical and Computer Engineering, speaking to Politiken
USB data blockers for public charging
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Records Taken and Exposure Still Unknown
The supplied reporting does not establish how many records were retrieved, which categories of personal information were copied, or whether data is still held outside the CPR system. The figure of around 8.8 million CPR numbers describes the scale of the information linked to the breach, not a confirmed count of individual records downloaded or misused.
It is also unclear whether the reported ‘123456’ passwords were the credentials used in the initial intrusion, whether they were active throughout the access period, or what other authentication safeguards were present. Politiken’s report says at least three accounts used the password, including an administrator account, but the supplied material does not identify those accounts or independently verify their password histories.
The attacker’s account of using a former employee’s leaked password and creating programs to retrieve and store information is an allegation attributed to an anonymous source. The claim that the data will not be sold or published is likewise the person’s stated intention, not a guarantee about what will happen to the information. The available material does not describe any official findings, notifications to affected people, or confirmed downstream misuse.
portable password manager security keys
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The next developments to watch for are details from Pays and relevant authorities about the investigation, the data involved, and steps taken to secure the company’s access to the CPR system. The supplied reports do not set out a timeline for further disclosures or identify a scheduled public update.
Further clarification is needed on whether the compromised accounts have been disabled or reset, how the reported access was detected, and whether investigators have determined what was copied. Confirmation of those points would help establish both the practical exposure for people whose CPR numbers were implicated and whether information remains at risk.
For now, the confirmed company statement is that Pays’s authorized access was abused in an attack. The password details, the alleged attacker’s route into the system, and the person’s claims about handling the data should be read with their attributions intact until corroborated by an investigation or additional reporting.
multi-factor authentication security device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What happened in the Danish CPR breach?
Pays ApS confirmed to TV 2 that an attack abused the company’s authorized access to search Denmark’s CPR register. Politiken reported that information linked to around 8.8 million CPR numbers was involved.
Was ‘123456’ used as a password?
Politiken reported that at least three Pays accounts, including an administrator account, used ‘123456’. The supplied material does not include a separate confirmation of those account details from Pays or an authority.
How long did the reported access last?
The report says the hacker had access to the CPR register from September 10 for 21 days and 17 hours. It does not provide further details in the supplied material about when the access was discovered.
What information was exposed?
The breach involved information linked to around 8.8 million CPR numbers, but the available reporting does not identify exactly which personal details were retrieved or how many records were copied.
Has the data been published or sold?
The anonymous person who told Politiken they carried out the attack said there were no plans to sell or publish the information. That is the person’s claim; the supplied reporting does not independently confirm whether data was shared or what happened to any copies.
Source: hn
Columbus Day / Indigenous Peoples' Day Picks
long weekend sales
As an affiliate, we earn on qualifying purchases.
