At least three user accounts, including an administrator account, at the Danish IT company Pays used the weak password “123456” when hackers accessed Denmark’s CPR register, exposing personal data linked to around 8.8 million CPR numbers. The hacker gained entry by exploiting leaked credentials and maintained access for nearly 22 days, using automated programs to extract data; authorities discovered the breach after unusually high CPR search activity was detected. The company confirmed the attack, and experts criticized the poor password security, highlighting systemic vulnerabilities in protecting sensitive national registry information.
https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/

