`123456’ password used in massive Danish CPR data breach
A breach of Denmark's Central Person Register, a national identity database, has been linked to an IT company called Pays where at least three accounts — including an administrator account — were secured with the password '123456'. The incident exposed data from one of Denmark's most sensitive government registries.
Why this matters: Denmark's CPR register is not a generic database. It holds identifying information tied to nearly every person living in the country, used across healthcare, banking, and government services. When the company managing access to that system leaves an admin account protected by '123456', that is not a technical failure. It is a decision — someone chose convenience over basic security on a system that affects millions of people. The real accountability question is not just how hackers got in, but why Pays was trusted with this access in the first place and who was checking.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.