`123456' password used in Danish CPR data breach
baal80spam
382 points
195 comments
October 10, 2026
Related Discussions
Found 5 related stories in 94.7ms across 9,063 title embeddings via pgvector HNSW
- Denmark data breach exposes 8.8M people's personal data clan · 475 pts · October 05, 2026 · 66% similar
- 24,650 internet-accessible BMCs leak password-derived hashes before login ilreb · 20 pts · July 28, 2026 · 53% similar
- Terabytes of credentials leaked in supply-chain attack RattlesnakeJake · 42 pts · August 13, 2026 · 49% similar
- UK.gov begins killing off passwords for 23M users jjgreen · 20 pts · September 14, 2026 · 48% similar
- France's tax authority had data stolen on 680k taxpayers rzk · 53 pts · August 14, 2026 · 46% similar
Discussion Highlights (19 comments)
donalhunt
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen. Equivalent to social security information in the US I guess.
INTPenis
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here! Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
piker
That’s the same combination I have on my luggage!
m00dy
lol, it's a joke right ?
lifestyleguru
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
zweifuss
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
sneak
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
tokai
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
sokols
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
croes
Did they have MFA?
zkmon
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal. It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
mattlondon
If only they had insisted on a secure 8 character password!
ano-ther
So it was actually two weaknesses: * The non-password at a two-person IT company (Pays ApS) * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
caaqil
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
ionwake
Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks. I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder. You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay. I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
aussieguy1234
They forgot to write it on a post-it note attached to the monitor /s
ZuoCen_Liu
Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...
bricss
If only there was an algorithm for password strength estimation > . <
shevy-java
That's my password!!! Thieves give it back now!