A massive breach of Denmark’s central Civil Registration (CPR) system exposed personal details tied to about 8.8 million CPR numbers after attackers accessed the register through credentials belonging to Pays ApS. Review of the leaked access shows at least three Pays accounts - including an administrator account - used the password 123456. The company confirmed its legal access was abused; cybersecurity experts called the password security “hopeless,” saying such trivial credentials left the system effectively an open door. The unauthorized access window began on 10 September and lasted 21 days and 17 hours before being stopped, though preliminary work suggests active data extraction may have ended around 20 September.
The intruder said initial entry came via a leaked password from a former employee of a small Danish firm, then ran two custom programs to pull and store CPR data externally. The hacker claimed no plans to sell or publish the material. Private companies and associations can be granted legitimate CPR access for tasks like obtaining customer addresses, and Pays ApS reportedly had two employees. The combination of excessive access privileges, weak credential hygiene, and inadequate detection allowed a large-scale exfiltration of sensitive national identity data, exposing systemic security failures in how external partners are managed.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.