Security

Simple Password '123456' Linked to Massive Danish Data Breach

By

digital security lock, server room, data breach illustration Simple Password '123456' Linked to Massive Danish Data Breach
Illustration for this article

A significant data breach at Denmark's Central Population Register (CPR) has exposed the personal information of 8.8 million people, encompassing residents, deceased individuals, and citizens living abroad. The incident, which came to light following an official disclosure by the Danish Ministry of Research, Education and Digitalisation on October 5, 2026, has raised serious concerns about digital security practices within systems holding sensitive national data.

The breach's origins were traced to irregular activity detected in the CPR system on the evening of Friday, October 2, 2026. This activity, which had been occurring throughout September, prompted an immediate investigation. Over the subsequent weekend, the full extent of the unauthorized access was uncovered, leading to the notification of the Danish Data Protection Agency (Datatilsynet) on Sunday, October 4, 2026.

Investigators determined that the attackers gained access by misusing a private Danish company's legitimate credentials to search the CPR system. The compromised access allowed the retrieval of names, addresses, and CPR numbers, but importantly, it remained within the limits of information that private companies are typically authorized to access. The company at the center of the breach, Pays ApS, based in Odense, confirmed to TV 2 on Friday, October 9, 2026, that its system had indeed been compromised.

Crucially, reports from Politiken, as cited by The Copenhagen Post on October 10, 2026, revealed a glaring security lapse: at least three user accounts at Pays ApS, including the company's administrator account, were protected by the notoriously weak password "123456." This simple, easily guessable password served as the entry point for unauthorized parties to access the highly sensitive national database, a revelation that has shocked cybersecurity experts.

Professor Jens Myrup Pedersen from Aarhus University's Department of Electrical and Computer Engineering sharply criticized Pays' password security as "hopeless." He emphasized the obvious vulnerability, stating, "A password like '123456' is one of the very first things you would guess if you took a list of common passwords." The simplicity of the password underscores a fundamental failure in basic cybersecurity hygiene.

The unauthorized access to the CPR register began on September 10 and persisted for a total of 21 days and 17 hours, before being successfully stopped on October 2. Preliminary investigations suggest that the most active period of unauthorized data retrieval concluded around September 20, approximately ten days after the initial breach.

An anonymous hacker has claimed responsibility for the breach, telling the Danish newspaper Politiken that they gained initial access using the "123456" password. The hacker further alleged that this password belonged to a former employee of a small Danish company. Following this initial access, the hacker claims to have developed two computer programs specifically designed to retrieve information from the CPR system and store it externally. The hacker told Politiken there were no plans to sell or publish the information, expressing profound shock at the discovered security weaknesses and comparing the situation to leaving nuclear material unattended. An IT security expert at Defend Denmark, Emil Hørning, reviewed data allegedly used by the hacker and found the account credible and the method plausible.

In response to the incident, the Danish Ministry of Research, Education and Digitalisation has initiated several measures to prevent similar occurrences and has requested a comprehensive security review of the entire CPR system. The register's administration has promptly revoked the compromised company's access, and law enforcement, in collaboration with other relevant authorities, has launched an investigation into the case.

The public reaction has been swift and significant. The Danish cyber hotline extended its operating hours to provide advice to residents and businesses on digital security, fraud prevention, and cyberattacks, and to assist individuals in creating credit warnings. By October 7, nearly one million Danes had registered a credit warning, a dramatic increase from just under 250,000 on October 1, reflecting widespread concern among the populace.

While the immediate aftermath of the breach is being managed, several critical questions remain unanswered. Official statements have not yet clarified how the unauthorized parties gained access to Pays ApS's systems beyond the weak password. It is also still unknown whether the unauthorized parties have retained or used the data, despite the hacker's claims of no intent to sell or publish. The identities of those ultimately responsible for the breach have not been confirmed by authorities. Furthermore, it is too early to determine if affected individuals will need to be issued new CPR numbers, and authorities are still in the process of mapping the entire extent of the incident. This breach serves as a stark reminder of the paramount importance of robust password practices and comprehensive cybersecurity measures in safeguarding sensitive personal information.