`123456' password used in Danish CPR data breach

229 points · 137 comments on HN · read original →

Points and comments are a snapshot, not live.

Hackers breached Denmark's CPR register via passwords like '123456'.

A breach of Denmark's CPR register exposed data on 8.8 million people. Hackers gained access through Pays ApS, a two-employee IT company, using passwords including '123456' for at least three accounts, one an administrator. The hacker had access from September 10 for 21 days, using a leaked former employee password. 14 million CPR searches were made. Authorities detected the breach via an unusually large invoice.

What commenters are saying

Commenters were shocked but not surprised, noting the breach reflects pervasive security failures. Several highlighted that the company had only two employees, questioning oversight. Some debated the secrecy of CPR numbers versus US SSNs, noting CPR is often treated as public. Others called for accountability, audits, and better incentives, with a split between blaming the company's password practices and systemic failures in privatization and cost-cutting.