CPR breach firm scored 1/10 after 123456 password found

Picture of Gitonga Riungu

Gitonga Riungu

CPR breach firm scored 1/10 after 123456 password found

An IT security expert has given the Odense company at the center of Denmark’s CPR data breach a score of 1 out of 10 for security, after reporting showed an employee password of “123456” and no two-factor authentication.

DR reported on Friday, October 9, 2026, that a small company on Funen was used by a hacker to obtain 8.8 million CPR numbers. According to DR, the company held lawful access to the CPR register, and that access was compromised.

The company is Pays, based in Odense. It confirmed to TV 2 that it was the business targeted in the attack. Managing director and owner Sophie Laursen wrote to TV 2 that the company’s lawful access to search for information in the CPR system had been misused.

DR says it put the story and the expert criticism to Pays, but the company had not responded by the broadcaster’s deadline.

Password “123456” and no two-factor verification

Like Politiken, DR has reported that an employee password was “123456” and that the company did not use two-step verification. Politiken reported the hacker’s own account of the method, and says experts assessed both the method and the data as highly credible.

IT security expert Peter Kruse, who is also a city council member for Liberal Alliance in Skanderborg Municipality, told DR this was a blatant breach of good security practice. He said such a password could be guessed in extremely short time even by someone who did not know it. On a scale of 1 to 10, he gave the company’s security a 1.

DR also found a publicly accessible subpage on Pays’ website through ordinary internet searches. It resembled a tool for validating or cleaning CPR data, email addresses and addresses. Archived versions show traces of the page going back to the beginning of 2023, and it went offline late Thursday.

DR notes it could not establish whether the page had been used, or could be used, to validate CPR data. Kruse said it was still a problem that the page sat openly searchable online. He added that such pages spark curiosity among hackers because they look poorly designed.

Criticism of the authorities’ own requirements

Kruse also directed his criticism at the authorities. He questioned why no automatic function stops the system when very large volumes of data are pulled from the register. Over 13 million queries were made in the system in 10 days, which he called wild.

According to Kruse, a password for the CPR register may not be longer than eight digits. He called that an outdated form of authentication compared with what ordinary users must meet on social media, email and streaming services. Jacob Herbst, chair of the Danish Cyber Security Council, told DR that authorities must be expected to follow up on the requirements they set, and that something suggests this did not happen here.

DR contacted digitalisation minister Christina Egelund (M) for comment, and the ministry’s press office had not responded by deadline. On Monday the minister said there was clearly a flaw in the CPR system’s security arrangements. TV 2 has reported that the unauthorised access began on September 10, 2026, apparently ended on September 20, and was discovered on October 2.

What the CPR breach means for foreign residents in Denmark

The CPR number is the personal identification number issued to everyone registered as a resident in Denmark, including internationals on work, study and family permits. It is used for healthcare, tax, and to open a bank account. Politiken reported on October 5, 2026, that the compromised information included names, addresses and CPR numbers for around 8.8 million people.

Because the register covers people who have held a CPR number over time, not only current residents, the affected group is larger than Denmark’s population. Politiken also reported that the company’s CPR service access was closed, the case was reported to the Danish Data Protection Authority, and police are investigating. Earlier CPR incidents include the DTU data breach and a trial over selling CPR numbers to criminals.

author avatar
Gitonga Riungu Writer
Gitonga Riungu covers sustainability, business and politics in Denmark. Gitonga's articles add context and perspective so readers understand why a story matters.
Danish News in English for Internationals - The Danish Dream

Get the daily top News Stories from Denmark in your inbox