`123456' password used in Danish CPR data breach

baal80spam 382 points 195 comments October 10, 2026
cphpost.dk · View on Hacker News

Discussion Highlights (19 comments)

donalhunt

In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen. Equivalent to social security information in the US I guess.

INTPenis

I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here! Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

piker

That’s the same combination I have on my luggage!

m00dy

lol, it's a joke right ?

lifestyleguru

For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.

zweifuss

I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.

sneak

The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?

tokai

Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.

sokols

I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.

croes

Did they have MFA?

zkmon

I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal. It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

mattlondon

If only they had insisted on a secure 8 character password!

ano-ther

So it was actually two weaknesses: * The non-password at a two-person IT company (Pays ApS) * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).

caaqil

It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.

ionwake

Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks. I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder. You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay. I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.

aussieguy1234

They forgot to write it on a post-it note attached to the monitor /s

ZuoCen_Liu

Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...

bricss

If only there was an algorithm for password strength estimation > . <

shevy-java

That's my password!!! Thieves give it back now!

Semantic search powered by Rivestack pgvector
9,063 stories · 85,264 chunks indexed