The Daily Inference
AI & Technology · News · Developing

Report: 8.8 Million Danes' IDs Taken Through a '123456' Password

Authorities confirm that names, addresses and national ID numbers for about 80 percent of Denmark's register were taken through a small company's account. Politiken reports that the account was protected by one of the world's most common passwords.

Developing: this story is still unfolding and details may change.

Names, addresses and national ID numbers of about 8.8 million people in Denmark were taken through one small company's account [3][4], and the newspaper Politiken reports that the account was guarded by the password "123456" [1][2].

The breach itself is confirmed. The Danish ministry of research, education and digitalisation disclosed it on October 5, 2026, and said the data came from the Central Person Register, known as the CPR [3][4]. The register holds about 11 million records, so roughly 80 percent of it was reached [3][5].

The password detail rests on Politiken's reporting and an anonymous hacker's account, and authorities have not confirmed it.

A two-person company with a key to the national register

According to Politiken, at least three user accounts at Pays ApS, an IT company in Odense on the island of Funen, used "123456" as the password. One of them was the administrator account [1][2]. Politiken reviewed data from the breach [1][2]. Company records list Pays ApS as having two employees as of July 2026 [1][2].

Pays ApS confirmed to TV 2 on October 9 that its access had been compromised. Managing director Sophie Laursen said the company's "legal access to search for information in the CPR system has been abused" [1][2].

That legal access is routine. Under section 38 of the CPR Act, private companies and associations with a legitimate need, such as checking the addresses of customers or members, can be granted the right to search the register [1][5].

What the hacker says

An anonymous hacker told Politiken they were behind the attack and that getting in was not particularly difficult. The hacker said they used a leaked password belonging to a former employee of the company [2].

They then wrote two programs to pull CPR information out of the system and store it elsewhere, and said they have no plans to sell or publish it [2]. Politiken reported that access ran from September 10 until it was stopped on October 2, a span of 21 days and 17 hours [1][2].

The hacker said they were "really shocked" by the weaknesses and compared the situation to someone leaving plutonium unattended at a train station [2].

Politiken passed the data file the hacker supplied to Emil Hørning, an IT security expert at the Danish firm Defend Denmark. He said the account looked credible and the described method was plausible [2]. The National Special Crime Unit, which is investigating, said it is "too early to say at this point who is behind it and what method has been used" [2].

The technical picture so far points to plain misuse of valid access. A security vendor's timeline says no malware or software vulnerability was involved [7].

Jens Myrup Pedersen, a professor at Aarhus University's Department of Electrical and Computer Engineering, called the company's password security "hopeless" and said: "There is really no security, it is an open door. A password like '123456' is one of the very first things you would guess if you took a list of common passwords" [1][2].

Found by the bill, not by an alarm

No security alert caught the intrusion. An invoice did.

About 14 million CPR searches had been run through the company's credentials, according to Politiken, and the CPR administration received an unusually large bill for them [2]. Mikkel Leihardt, a department head at the ministry, said: "There is a very large amount being invoiced, which makes one aware that there has been a lot of activity" [2].

The administration detected irregular activity on the evening of Friday, October 2. Over the following weekend it worked out the scale, notified the Danish Data Protection Agency on October 4, and went public the next day [3][4][7]. The agency described a very large number of automated searches aimed at finding valid CPR numbers, which points to scraping, the automated copying of records at scale [4][5][6].

Preliminary investigations suggest the unauthorised activity ended around September 20, which would leave about 12 days between the last searches and the discovery [1][2].

Why the number matters

The CPR number is a 10-digit identifier used for healthcare, banking, taxes, government services and legal identification, and it is meant to stay with a person for life [3][5][6].

Danes do not guard it like a card PIN. It goes on forms, to pharmacies and to landlords. What protects a person is that a stranger has not usually been able to pair it with a name and a home address, and in this breach all three were taken together. People registered with name-and-address protection, a status for those at heightened personal risk, were not affected [3][5].

The ministry warned that the data could be used in fraud attempts. It told people never to hand over passwords or confidential information by phone, email or similar channels, even if the caller knows their name, address and CPR number [3][5]. Authorities urged citizens to set up credit warnings through borger.dk [4][5].

An old weakness, newly visible

This is not the first scare around the register. In 2015, two unencrypted CDs holding CPR information on more than 5 million people were mistakenly delivered to the Chinese Visa Application Centre in Copenhagen. Authorities said then there was no evidence the data had been copied or leaked [4].

The design problem is the same in both cases. A national database is only as safe as the least careful holder of a key to it. Minister Christina Egelund called the breach "a deeply serious incident" and acknowledged that security around private companies' access "was inadequate" [3][4][5][6]. She has ordered a thorough review of the system [4][5][6].

A password like "123456" is a failure of the company that chose it, if Politiken is right. But the register let a two-person firm query it on a scale of millions. That is the state's part of the story, and the review will have to deal with it.

Egelund said the authorities, together with all relevant agencies, are "in the process of mapping the entire extent of the incident" [3][4]. She said it is too early to decide whether affected people will need new CPR numbers [5]. The police investigation and the Data Protection Agency's inquiry continue, and no fines or charges have been announced.

Every edition in brief, three times a day, on our Telegram channel, on Bluesky and on Threads.

Sources
  1. `123456' password used in massive Danish CPR data breach - The Copenhagen Post Hacker News
  2. Hacker claims simple password allowed access to 8.8 million Danish CPR numbers - The Copenhagen Post cphpost.dk
  3. Data breach at Denmark's population register exposes 8.8 million people - Help Net Security helpnetsecurity.com
  4. Data breach at Denmark's national population register exposes 8.8 million people | The Record from Recorded Future News therecord.media
  5. Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account thehackernews.com
  6. Denmark CPR Data Breach Exposes 8.8M Records [2026] shattered.io
  7. Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million via Company Account in 2026 - Rescana rescana.com