`123456’ password used in massive Danish CPR data breach
Hackers reached Denmark's CPR register after at least three Pays accounts, including an admin, used "123456".
Ritzau reports that hackers reached Denmark's Central Person Register (CPR) through the Funen-based IT company Pays. At least three Pays user accounts, including an administrator account, were protected only by the password "123456" when the intruders gained access. The incident is described as a massive breach of the national civil registration system, which holds core identity data on Danish residents.