INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Danish CPR data breach linked to weak password 123456

| 2026-10-10 20:42 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A major breach of Denmark's Central Person Register (Denmark Central Person Register) occurred from 10 September for a total of 21 days and 17 hours, allowing hackers to access the register. The attackers used the password "123456", including an administrator account at Pays, a Funen-based IT company linked to the breach. At least three user accounts at Pays used this password when gaining unauthorized access to Denmark's CPR register (Denmark’s CPR register). This data breach is classified as a Data Breach cyber operation type targeting Denmark (Target Country), with Denmark Central Person Register being the identified entity affected, and Funen being another identified entity linked to the incident.
Technical Mitigations AI-generated
• Use a stronger password for administrator accounts, such as multi-factor authentication or a unique password. • Monitor and patch Pays' systems to address the vulnerability in their login process that allowed "123456" passwords. • Implement an account lockout policy after multiple failed login attempts to prevent similar breaches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORDICS NORDICS
Incident Timeline
‎10 September
Threat actors used the password `123456` to access the CPR register for 21 days and 17 hours starting from September 10.
general_metric 17 hours
‎2026/10/10
Threat actors gained access to Denmark's CPR register by exploiting at least three user accounts, including an administrator account, that used the password "123456".
organisation Denmark Central Person Register
organisation Denmark’s CPR register
organisation Funen
Intelligence Sources