At least three accounts at the Funen-based IT company Pays used the password '123456' when hackers accessed Denmark's CPR register, including an administrator account. The breach exposed information linked to around 8.8 million CPR numbers. Pays Ap S, based in Odense, confirmed it was the company whose legal access to the CPR system was abused.
The hacker had access from 10 September for 21 days and 17 hours, gaining entry via a leaked password from a former employee of a small Danish company. Jens Myrup Pedersen, professor at Aarhus University, called the password security 'hopeless', stating '123456' is one of the first passwords guessed in common password lists. He said it was 'a matter of time before things went wrong.' Private companies can access CPR data for legitimate needs like address verification.
Pays Ap S had two employees as of July 2026, according to Denmark's Central Business Register. The hacker claimed they had no plans to sell or publish the stolen data.
Source: Hacker News · Summarized by HeadlinesBriefing