43
votes
Denmark government hack leaked 8.7 million citizen's ID's: the password was "123456"
Link information
This data is scraped automatically and may be incorrect.
- Title
- Afsløring: Fynsk virksomhed er centrum for massivt CPR-databrud
- Authors
- Frederik Hagemann-Nielsen, Alexander Hecklen, Louise Dalsgaard, Christian Panton, Emil Hobolt Mortensen
- Published
- Oct 9 2026
- Word count
- 280 words
Article in Danish, some translated snippets:
The company also didn't use 2FA, and login page for their access was publicly available: article link.
The many troubling things a Danish CPR number (ID) can be used for include counterfeit, phising, scamming, obtaining even more personal information on you, even taking out loans: article link
Previous thread: link
Spaceballs_password_scene.gif
This has been a well known joke since the mid 80s, come on guys.
I know, I had the exact same urge to say that I have the same combination on my luggage.
My work password includes
123to satisfy the number requirement because it's easy to quickly type...It's easy to incorporate things like this into a good password though. Also my [current] work password includes 123 too...
I just need to remind everyone that the danish presidency of the Council of the EU were the ones that reintroduced Chat Control last year (on their very first day).
I had to google Chat Control because I hadn't heard of it before.
Thanks... I hate it. This isn't going to protect any children from pedophiles, it's just going to make it a thousand times harder for law enforcement to do their jobs.
I think this validates @smoontjes's point about Danish systems being 'hilariously bad'.
Regular bad would be Admin1!
123456 tips it over the edge
shoulda been hunter2
That just shows as ******* on my screen
So I just told my mom about this and asked her to guess the password. Her response: "12345". Off by a single digit. Frankly at that point you might as well use "password" as a password.
All I can think is that there's some idiot in the chain with too much power who would complain about passwords being too complicated. And that the actually trained experts were forced to use 123456 as a password to placate them, because they were too high-ranking and connected to just deny access to these critical systems or fire. It's the only explanation that makes sense to me, because the alternative is just... Absolute incompetence everywhere.
In case the title is not clear, it is not the CPR system that had that password. It was the admin system of the small private company where their access was misused through. The real problem is how lenient access to the system has been given and how little monitoring of usage analogies there is.