HyperAIHyperAI

Command Palette

Search for a command to run...

Security

"123456" Password Exposes 8.8 Million Danish CPR Records

A major security breach of Denmark’s national Civil Registration System (CPR) has exposed the personal data of approximately 8.8 million individuals, prompting a nationwide investigation and urgent cybersecurity advisories. The compromise was detected in early October when authorities flagged an unusually large invoice generated by Pays ApS, a small Odense-based IT firm legally authorized to query the register. Preliminary findings indicate that unauthorized actors maintained access to the system for 21 days and 17 hours, beginning on September 10, with intensive data extraction likely occurring over a concentrated 10-day period in September. According to investigators and anonymous claims made to media outlets, the attackers initially gained entry using a leaked password belonging to a former employee of a separate Danish firm. From there, they exploited severely deficient security protocols at Pays ApS, where at least three user accounts, including the primary administrator account, were secured with the easily guessable password 123456. The hacker responsible stated that developing custom scripts to automate searches and extract data was straightforward, and asserted there are no current plans to monetize or publish the stolen information. Cybersecurity experts have condemned the vulnerability. Professor Jens Myrup Pedersen of Aarhus University described the company authentication standards as hopeless, noting that reliance on common passwords represents a critical failure in basic digital hygiene. In response, the Ministry of Research, Education and Digitalization has ordered a comprehensive security audit of the CPR infrastructure. The National Special Crime Unit and the Danish Data Protection Agency are actively investigating the incident, which authorities suspect may involve cross-border cybercrime or identity fraud. The breach has triggered immediate operational adjustments across Danish public and private sectors. Samsik, the Agency for Public Security, issued a formal advisory warning that CPR numbers can no longer be trusted as a sole identifier for citizen verification. Consequently, pharmacies and healthcare providers are implementing stricter authentication measures, requiring physical or digital health cards, MitID credentials, or multi-factor verification before dispensing medication or sensitive health records. The Confederation of Danish Industry cautioned that prolonged restrictions on CPR access could significantly increase administrative overhead for businesses reliant on real-time identity validation, while simultaneously elevating fraud and data-mismatch risks. To mitigate potential fallout, the Danish Agency for Societal Security has temporarily extended its cyber hotline operating hours to assist citizens and enterprises with fraud prevention and credit warnings. Authorities maintain that core system integrity remains intact, but emphasize that the incident underscores the urgent need for robust, multi-layered authentication across all government-linked digital infrastructure.

Related Links