TL;DR
Get business pricing on networking and server gear
- Business-only prices and quantity discounts
- Tax-exempt purchasing
- Multiple users, one account, clear invoices
Politiken reports that at least three Pays ApS accounts, including an administrator account, used the password “123456” when attackers accessed Denmark’s CPR register through the company. The breach involved information linked to about 8.8 million CPR numbers, but it remains unclear what data was taken or whether it was shared.
At least three accounts at Pays ApS, including an administrator account, reportedly used the password “123456” when attackers accessed Denmark’s central civil registration system through the company. The breach involved information linked to about 8.8 million CPR numbers, according to reporting by Politiken, which reviewed data the hacker allegedly used to gain access.
Pays ApS, an IT company based in Odense, confirmed to broadcaster TV 2 that it was the company whose access to the CPR system had been compromised. Managing director and owner Sophie Laursen said in an email that the company had been attacked and that its lawful access to search the register had been abused. The report does not establish that Pays itself operated the CPR register; the company had authorized access to search it.
Politiken reported that the attacker had access to the register from September 10 for 21 days and 17 hours. The newspaper said at least three Pays user accounts used “123456,” including an administrator account. The reported password details and the account information were based on material Politiken reviewed; the source material does not identify who established the accounts’ password settings or when they were set.
An anonymous person claiming responsibility told Politiken that access was initially obtained with a leaked password belonging to a former employee of a small Danish company. The person also claimed to have created two programs to retrieve information from the register and store it elsewhere. These are the hacker’s account of the operation, not independently established facts in the material provided. The person told the newspaper there were no plans to sell or publish the information.
Risks to Civil Registration Data
The reported exposure matters because the CPR register holds personal information about people living in Denmark and people previously registered there. Information associated with roughly 8.8 million CPR numbers could affect a broad group, although that figure does not by itself show that every record was accessed, copied or exposed in the same way.
The account illustrates the risks that can arise when public databases are accessed through outside organizations. Danish companies and associations may receive register access when they have a legitimate need, such as checking customer or member addresses. In this case, the immediate reported weakness concerned accounts at an authorized company, rather than a claim that the register’s central systems were directly breached.
Professor Jens Myrup Pedersen of Aarhus University told Politiken the password security was “hopeless.” His assessment underscores why the reported use of a widely guessed password on an administrator account has drawn attention. It is an expert’s characterization of the reported security practices, not a published technical audit of the full incident.
password manager for secure password storage
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Pays Accessed the CPR Register
Denmark’s CPR system is the country’s central civil registration database. Its records contain personal information on people who live in Denmark or have previously been registered there. The source report says that private companies and associations can be granted access where they can show a legitimate purpose, including obtaining address information about customers or members.
The company named in the report, Pays ApS, is based in Odense. Denmark’s Central Business Register listed it as having two employees in July 2026. Pays confirmed its identity as the company involved after Politiken reported on the breach. The available reporting describes misuse of the company’s legal search access, while the hacker separately claimed the initial route involved a former employee’s leaked password.
The reports describe a period of access beginning September 10, lasting 21 days and 17 hours. Politiken said it had reviewed data the hacker allegedly used to obtain access. The material provided does not give a precise date when the access ended, a detailed technical account from Pays or the register operator, or a full inventory of records involved.
“There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.”
— Jens Myrup Pedersen, professor at Aarhus University’s Department of Electrical and Computer Engineering, speaking to Politiken
multi-factor authentication device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Extent of Data Access Remains Unknown
The reports do not establish exactly which records or fields were accessed, how many individual records were retrieved, or whether all information linked to the roughly 8.8 million CPR numbers was exposed. The figure describes the scale associated with the breach, not a confirmed count of records copied or published.
It is also unclear whether the information was transferred beyond the systems described by the anonymous person, whether it has been shared with anyone else, and whether the claim that it will not be sold or published can be relied on. The hacker’s account of using a former employee’s leaked password and creating retrieval programs has not been independently verified in the supplied reporting.
The source material does not include findings from an official investigation, a technical explanation from Pays, or a statement from the operator or authorities responsible for the CPR register. It therefore does not settle how the account passwords were managed, what safeguards were in place, or what corrective steps have been taken.
As an affiliate, we earn on qualifying purchases.
Investigation and Security Measures
The next developments to watch for are official findings about the scope of the access and further details from Pays or the relevant CPR authorities. The source reports do not specify an investigation timetable, announced changes to account access, or a planned notification process for people whose information may have been involved.
Any fuller account will need to distinguish the records merely within reach of the compromised access from information actually retrieved or retained. It should also clarify how the access was stopped, whether the reported accounts have been secured, and what steps are being taken to prevent similar misuse of authorized third-party access. Those details remain unconfirmed in the available reporting.
As an affiliate, we earn on qualifying purchases.
Key Questions
What happened in the Danish CPR data breach?
Politiken reported that attackers abused Pays ApS’s authorized access to search Denmark’s CPR register. The access reportedly lasted 21 days and 17 hours from September 10.
What is the significance of the “123456” password?
Politiken reported that at least three Pays accounts, including an administrator account, used the password. The report does not specify when the passwords were set or independently detail the full security setup.
How many people may be affected?
The breach involved information linked to about 8.8 million CPR numbers. That figure does not confirm how many records were actually accessed, copied or disclosed.
Has the information been published or sold?
Not according to the anonymous person claiming responsibility, who told Politiken there were no plans to sell or publish it. That statement has not been independently verified, and the available reports do not establish whether data was shared elsewhere.
What has Pays confirmed?
Pays ApS confirmed to TV 2 that it was the company whose legal access to search the CPR system was abused. The supplied reports do not include the company’s detailed technical findings or a full account of remedial actions.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
