# Pays accounts used "123456" during Danish civil registry breach

_Published Saturday, October 10, 2026 at 6:49 AM EDT · Security · Latest · Tier 2 — Notable_

At least three accounts at Danish IT company Pays used the password "123456" when hackers accessed Denmark's central civil registration database, Politiken reported, including an administrator account. The breach exposed information linked to around 8.8 million CPR numbers, which identify people living or previously registered in Denmark.

Pays confirmed on Friday that attackers abused its authorized access to the register. The hacker had access from 10 September for 21 days and 17 hours. An anonymous hacker claimed entry began with a leaked former employee's password and that two programs retrieved and stored registry information externally. Those claims do not establish that the weak passwords identified by Politiken were the initial entry point.

## Sources

- [cphpost.dk](https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/)

---
Canonical: https://techandbusiness.org/newswire/yxg4EuXbvttkNH5eLWF-E9
Published: 2026-10-10T10:49:14.712Z
Story chronology: 2026-10-10T09:51:49.000Z
Retrieved: 2026-10-10T13:00:00.276Z
Publisher: Tech & Business (techandbusiness.org)
