Danish CPR Breach Exposed 8.8M Records; Compromised Firm Used '123456' as Admin Password
jonerp · x · 2026-10-11
New details in Denmark's massive CPR registry breach: at least three accounts at IT firm Pays — including an administrator account — used the password "123456" when hackers gained access, Politiken reports.
Key facts:
- The breach exposed data tied to 8.8 million CPR numbers, Denmark's central civil registration system;
- The hacker held access for 21 days and 17 hours starting September 10;
- Odense-based Pays confirmed its legal access to query the registry was abused; CEO Sophie Laursen acknowledged the attack;
- Aarhus University professor Jens Myrup Pedersen called the password security "hopeless" — "an open door";
- An anonymous hacker has claimed responsibility to the media.
More from Safety
- laya-guard: local guardrail for coding agents blocks 25/27 AgentDojo attacks at ~90ms — Extreme_Ad5709 · 2026-10-11
- Dev builds laya-guard: a 322M local model vets every coding agent command in ~90ms on CPU — Extreme_Ad5709 · 2026-10-11
- NIST frameworks already exist — the real question is whether AI companies implement them — AlexTensor · 2026-10-11
- AI Impacts press release headline itself was misleading, not just journalists — jessi_cata · 2026-10-11
- The "5% extinction risk" headlines were wrong — and the misframing went beyond journalists — jessi_cata · 2026-10-11
- AI Audit Found an Infinite-Mint Bug in XRP's $94B Codebase, Earning a $250K Bounty — julianweisser · 2026-10-11