Get a free audit

Field Notes / Breach Analysis

Denmark Lost 8.8 Million Records to the Password 123456. The Alarm Was an Invoice.

Someone ran about 14 million searches against Denmark’s national population register using the login of Pays ApS, a two-person firm in Odense with legal access. At least three of its accounts, one of them the administrator, used the password 123456, and there was no second factor. Nobody’s monitoring raised it. The company noticed because the bill for the searches was too big. Here is what happened, what is still only a claim, and the supplier login you should check in your own business this week.

Author
Red Team Partners
Read
9 MIN READ
Filed
11 Oct 2026
An employee working late in a small office, the kind of two-person firm that can hold a login to a national register.

01 Found on an invoice, three weeks in

Every CPR search costs money. Documents cited by TV 2 date the unauthorised access from 10 September to 2 October 2026, a total of 21 days and 17 hours. The CPR office’s report to the Danish Data Protection Agency says the activity itself appears to have ended around 20 September. The ministry went public on Monday 5 October Copenhagen Post, 9 Oct .

Put those dates in a row. The searches had probably stopped before anyone opened the invoice. The CPR office wrote that 14 million lookups “far exceeds the company’s customer base”. Pays told it the company had not run them. A firm of two had a login that could pull the whole country, and nothing between that login and the register asked why a two-person business needed 14 million answers in ten days.

DateWhat happened
Early 2023Archived copies show a public page on the Pays website that looks like a tool for validating CPR numbers, emails and addresses. DR found it through ordinary search engines.
10 Sep 2026Unauthorised access begins, per documents cited by TV 2. The attacker says 11 September.
c. 20 SepUnauthorised activity appears to end, per the CPR office’s preliminary findings.
2 OctAccess stopped.
5 OctThe digitalisation ministry announces the breach.
7 OctCredit warnings registered in Denmark reach about 970,000, up from just under 250,000 on 1 October.
9 OctPolitiken publishes the 123456 detail and an interview with a person claiming responsibility.

The minister for digitalisation, Christina Egelund, told Ritzau that “security around the CPR system has not been good enough” The Local . The ministry’s department head Mikkel Leihardt said the system itself is intact and that the data taken was mainly names and addresses. Laila Reenberg, director of the Agency for Public Security, went further: “One must expect that one can no longer identify oneself with CPR.” Pharmacies have started asking for more than a number before they hand over medicine Copenhagen Post, 9 Oct .

02 Six characters, three accounts, no second factor

The facts the Danish press has confirmed are blunt enough. At least three user profiles at Pays used 123456. One was the administrator. The company ran no two-step verification. Peter Kruse, a Danish security specialist, called it a flagrant breach of basic security practice and gave the firm one out of ten DR .

Then there is the claim. An anonymous person told Politiken they got in with a leaked password belonging to a former employee, wrote one program to pull CPR data and a second to store it elsewhere, and have no plans to sell or publish it. Emil Hørning of Defend Denmark, one of the experts Politiken showed the sample to, said the account looked credible and the method plausible The Local . The National Special Crime Unit says it is too early to name anyone, so treat the former-employee detail as the attacker’s version until the police confirm it.

We see the middle step more than any other. When our operators test a client’s external logins, the account that still works is rarely an admin someone forgot to protect. It is a leaver’s account on a supplier portal, a reseller dashboard or a lookup service, kept alive because it was “shared” or because the offboarding checklist only covered the main directory. The owner believes the person left two years ago. The login never got the message.

03 Who holds a key to your data

Most UK businesses have a Pays somewhere. It is the small agency with an API key to the CRM, the reseller who can look up customer accounts, the mailing house with a login to your order system, the contractor who built your address-validation tool in 2023 and still has the admin account. Their security is your security for every record they can reach, and you probably have never seen their password policy.

UK GDPR puts a clock on it. Under Article 33 a controller notifies the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. A processor tells the controller without undue delay UK GDPR Art. 33 . The ICO’s guide sets out what the report has to contain ICO . None of that helps if, like Pays, your supplier finds out from an invoice. Your 72 hours start when you become aware. The three weeks before that are still yours to explain.

Four checks would have turned the Danish case into a non-event, and each one fits in a week:

  • Every external login, every supplier login, a second factor. Including the old portal you gave a partner in 2022, and including admin accounts at the supplier’s end if they reach your data.
  • Leaver accounts closed everywhere they exist. Your directory is the easy part. The SaaS tools, partner dashboards and shared logins are where the old passwords keep working.
  • Known-breached passwords blocked. 123456 sits at the top of every leaked-password list. A login form that still accepts it is checking length, if that.
  • Volume limits and alerts on bulk data access. If a supplier account suddenly pulls a hundred times its normal volume, your team should hear it the same day, not on the bill.

Denmark is now asking millions of people to prove who they are some other way, because a two-person supplier’s administrator chose six digits. If one of your suppliers logged in tonight with a password from an old leak, who would notice first: your team, or your accounts department? We can find out in 14 days, from the outside, the way the attacker did. Get a free audit and see which of your logins still opens.

References

Sources

  1. The Copenhagen Post. Hacker claims simple password allowed access to 8.8 million Danish CPR numbers. 9 October 2026. cphpost.dk
  2. The Copenhagen Post. ‘123456’ password used in massive Danish CPR data breach. 10 October 2026. cphpost.dk
  3. DR. It-ekspert saver sikkerheden over i fynsk virksomhed, der er i centrum for CPR-databrud. October 2026. dr.dk
  4. The Local Denmark. Cybercriminal claims to have used simple password to hack Danish CPR system. 9 October 2026. thelocal.dk
  5. UK GDPR, Article 33: Notification of a personal data breach to the Commissioner. legislation.gov.uk. legislation.gov.uk
  6. Information Commissioner’s Office. Personal data breaches: a guide (72-hour reporting duty, UK GDPR Article 33). ico.org.uk