📣 Send us your press release
Site updates every 15 minutes
Technology

Denmark's CPR Register Leaks 8.8 Million Personal Records, Passwords Included '123456'

Denmark's national personal registration system (CPR) has suffered a massive data breach affecting approximately 8.8 million individuals. The leak was facilitated by weak security, including the use of '123456' as a password.

11 October 2026

Denmark is facing a significant personal data breach impacting roughly 8.8 million individuals, stemming from its central personal registration system, known as CPR. Security experts have strongly criticized the inadequate safeguards that led to the incident.

The breach occurred when unauthorized individuals gained access to the CPR system. A critical vulnerability was identified in the security practices of Pays ApS, a company involved in the incident, where at least three accounts used the password '123456'. One of these accounts was an administrator account, exacerbating the security lapse.

The CPR database holds personal information for current and former residents of Denmark. The scale of the leak highlights critical deficiencies in cybersecurity protocols. Jens Myrup Pedersen, a professor at Aarhus University, described the security as "appallingly bad," likening it to leaving the door open for hackers.

Pays ApS has confirmed the attack, stating that hackers exploited their legally obtained access rights to query the CPR system. The company is currently investigating the full scope and impact of the breach.

Original source: ithome.com