Admin account used password '123456' in massive Danish CPR breach

`123456' password used in Danish CPR data breach

Hackers accessed Denmark's CPR civil registration database for 21 days, exposing data linked to 8.8 million people. At least three accounts at Pays, the Funen IT company with legitimate access, used the password '123456', including an administrator account. A professor called the security 'hopeless'. The breach was discovered after an unusually large invoice for 14 million searches.

There is really no security, it is an open door. A password like '123456' is one of the very first things you would guess if you took a list of common passwords.

More from this day

2026-10-10