Abstract:
A recent large-scale personal information leak in Denmark exposed shocking account security issues. An investigation by the Danish media Politico found that at least three user accounts of the Funen information technology company Pays related to the incident used the extremely simple password "123456", including even the administrator account. As hackers used the legal data query rights of the companies involved to gain access to the Danish Central Population Registration System, the personal information of approximately 8.8 million registered persons was affected.

According to a report by the Copenhagen Post on October 10, the company involved, Pays ApS, is located in Odense, Denmark. The company had legal authority to query data from Denmark's Central Population Register (CPR), but this authority was later abused. Danish media Politico analyzed the leaked data related to the attack and found that at least three accounts involved used "123456" as the login password, and one of the accounts had administrator rights.
Jens Milup Peterson, a professor at the Department of Electrical and Computer Engineering at Aarhus University, severely criticized this and believed that such password security measures are almost useless. He pointed out that "123456" is one of the most common and easiest to guess passwords. When attackers try to crack accounts, they will often try such simple combinations first. Such weak account protection effectively opens the door to attackers.
It's hard to imagine a company taking worse password security measures than this, Peterson said, and it's almost only a matter of time before something like this happens.
Sophie Lawson, managing director and owner of Pays, previously confirmed to Danish TV 2 that the company was indeed the company whose legitimate data query rights were abused in this incident. She stated in the email that the company had suffered an attack and the attacker had taken advantage of the company's legally owned CPR system query permissions.
CPR is Denmark's central population registration system, which records the identity information of people registered in Denmark and is an important infrastructure for the country's public service system. Relevant information is widely used for identification and public services such as medical and administrative services. According to information previously released by the Danish government, the incident involved the names, addresses, CPR personal identification numbers and other information of approximately 8.8 million registered persons.
It should be noted that 8.8 million does not mean that all 8.8 million residents currently living in Denmark are affected. The CPR system also registers people who have emigrated abroad, deceased persons and others who were previously registered in Denmark, so the incident involves a large number of registration records in the system, not just the population currently living in Denmark.
The identity of the attacker in this incident has not been officially confirmed. An anonymous hacker previously claimed responsibility for the attack to Politico and said that he initially used a previously leaked password of a former employee to enter the relevant system. According to the hacker, after gaining access to the account, he wrote two computer programs: one to query and collect personal information from the CPR system, and the other to save the obtained data outside the system.
The hacker claimed that the whole process was not as complicated as imagined. He also said he had no plans to sell or publicly obtain the personal identification numbers and said he was shocked to discover how weak the system's security was. However, these statements currently mainly come from the hackers themselves, and the relevant facts still require further investigation and confirmation by the police and relevant departments.
The Danish government has previously confirmed that unauthorized persons used the data query rights legally owned by a Danish company to obtain a large amount of personal information of registered persons. After discovering abnormal activities, the CPR management department has terminated the system access rights of the company involved and reported the incident to the Danish Data Protection Supervisory Authority. The police have also cooperated with relevant departments to investigate.
Officially disclosed information shows that the CPR management department noticed abnormal behavior in the system in September on the evening of October 2, 2026, and subsequently confirmed that large-scale unauthorized data access had occurred. On October 5, the Danish Ministry of Research, Education and Digital Affairs officially announced the incident and announced that it would conduct a comprehensive security review of the CPR system to determine the specific course of the incident, its scope of impact, and further measures that need to be taken.
The most worrying aspect of this incident is not only the large number of people involved, but also the fact that the attackers did not necessarily exploit complex technical vulnerabilities in the central system itself, but the legitimate access rights of third-party companies and their weak account security measures. Enterprises originally obtained query permissions due to business needs, but they may have become an entry point for attackers to enter important public databases due to poor password management, insufficient account protection, or insufficient access monitoring.
The relevant system in Denmark allows qualified private companies and associations to query some information in the CPR when they have legitimate needs, such as obtaining the address information of customers or members. This arrangement can meet the needs of normal business activities and organizational management, but it also means that the security of the central database cannot rely solely on the technical protection of the system itself. It must also ensure that all external agencies that gain access rights comply with strict security requirements.
This incident also highlights the importance of administrator account protection. Administrator accounts usually have higher privileges. Once used without authorization, attackers may gain operational capabilities far beyond those of ordinary user accounts. The risk is further amplified when such accounts use easy-to-guess passwords and lack multi-factor authentication, abnormal access detection, and strict permission restrictions.
For ordinary people, the risks that may arise from large-scale personal information leaks will not disappear immediately as system access is closed. Once in the wrong hands, information such as names, addresses and PINs can be used for fraud, identity theft or targeted phishing attacks. Even if an attacker claims that the data will not be sold or disclosed, this statement cannot be taken as a guarantee that the information will not be disseminated further.
Danish authorities have reminded the public to be vigilant, especially against phone and email scams that use real personal information to build trust. Even if the caller can accurately state the individual's name, address, or CPR number, it does not mean that the caller is a trustworthy government agency, bank, or other legitimate organization. People should not provide passwords or other confidential information to each other as a result.
This incident is still under investigation. The true identity of the attacker, whether the data has been copied to multiple locations, and whether the leaked information has been further disseminated remain to be ascertained by relevant departments. The Danish government also needs to further evaluate the management mechanism for third-party companies to access the central population registration system and determine whether it is necessary to strengthen password requirements, administrator account protection, access rights review and abnormal query monitoring.
Judging from the issues exposed by the incident, protecting large public databases is not as simple as deploying advanced security equipment or patching technical vulnerabilities. Even if the central system itself has complete protection measures, as long as external partner companies can access data with legal permissions and the accounts of these companies lack basic security protection, the entire data system may still face serious risks.
A set of incredibly simple "123456" passwords may eventually become a key weak link in a large-scale personal information leak. This incident once again demonstrates that account security, third-party access management and continuous monitoring are also integral components of protecting national data infrastructure.
Comments