`123456’ password used in massive Danish CPR data breach
Hackers reached Denmark's CPR register after at least three Pays accounts, including an admin, used "123456".
Ritzau reports that hackers reached Denmark's Central Person Register (CPR) through the Funen-based IT company Pays. At least three Pays user accounts, including an administrator account, were protected only by the password "123456" when the intruders gained access. The incident is described as a massive breach of the national civil registration system, which holds core identity data on Danish residents.
- At least three Pays accounts used the password "123456".
- One compromised account was an administrator.
- Hackers accessed Denmark's national Central Person Register via the Funen IT firm.
- Reporting is based on further coverage from Danish news agency Ritzau.
Ritzau has more on the Denmark Central Person Register (CPR) breach: At least three accounts at the company linked to a major breach of Denmark’s CPR register reportedly used the password “123456”, including an administrator account. At least three user accounts at the Funen-based IT company Pays used the password “123456” when hackers gained access... Source
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.