'123456' password behind Danish CPR data breach

Original: `123456' password used in Danish CPR data breach

Why This Matters

CPR numbers underpin Denmark's entire public services infrastructure — exposure is severe.

A major data breach exposing Danish CPR (civil registration) numbers was traced to the password '123456', according to a report by the Copenhagen Post, highlighting basic credential security failures in sensitive government-adjacent systems.

The Copenhagen Post reports that a significant breach of Danish CPR data — the unique personal identification numbers assigned to all residents of Denmark — was enabled by the use of '123456' as a system password. CPR numbers are central to Danish civic life, used for everything from tax records to healthcare access, making exposure of this data particularly serious. While full details of the breach's scope, the responsible organization, and the number of affected individuals are not available from the headline alone, the use of the world's most commonly flagged weak password in a system holding sensitive national ID data points to a fundamental failure in basic security hygiene. Danish data protection authorities, the Datatilsynet, have strict GDPR-based obligations around personal data security, and breaches of this nature typically trigger mandatory reporting and potential fines. The incident joins a long list of high-profile breaches globally where trivially guessable credentials were the entry point.

Source

cphpost.dk — Read original →