databreaches.net 10 Oct 2026, 20:42 UTC

Pays Accounts Used ‘123456’ as Hackers Accessed Denmark’s CPR Data

THREE accounts at the Danish IT firm Pays, linked to the Denmark Central Person Register (CPR) breach, reportedly used the password "123456", with one being an administrator account. The detail comes from Politiken, cited by Ritzau in coverage of the CPR incident. The use of a simple, common password by multiple access points highlights weak credential hygiene at the organisation entrusted with CPR data.

Hackers gained access to the CPR register on 10 September and remained within the systems for 21 days and 17 hours before the breach was contained, according to the reporting. The post notes that the CPR exposure involved a substantial window of illicit access, underscoring the potential for sensitive personal data exposure during that period. The article also points readers to related coverage from The Copenhagen Post and Politiken for further specifics.

No CVEs, software versions, or other technical indicators are provided in the supplied material. This summary reflects only what the article itself states about credential use and access duration, and distinguishes confirmed access details from broader implications or conjecture. SOURCE_UNAVAILABLE

View full article

Article by CyberSIXT