HomeTech NewsCybersecurityPays ApS Confirms Its Access to Denmark's CPR Register Was Abused; '123456'...

Pays ApS Confirms Its Access to Denmark’s CPR Register Was Abused; ‘123456’ Passwords Reported

The Odense data company Pays ApS has confirmed to TV 2 that it is the firm whose lawful lookup access to Denmark’s national population register was abused. Politiken reports that at least three of its accounts used the password “123456”. That claim is reported, not confirmed by any authority.

What Pays ApS confirmed

Confirmed (Pays ApS statement, as reported by TV 2). Managing director and owner Sophie Laursen emailed TV 2: “Vi kan bekræfte, at vi er den virksomhed, der har været udsat for et angreb, hvor vores lovlige adgang til at søge oplysninger i cpr-systemet er blevet misbrugt.” TSN’s translation: “We can confirm that we are the company that has been subjected to an attack in which our lawful access to search for information in the CPR system has been abused.” [1] TV 2 says she declined an interview [1].

What CPR is

Denmark’s Central Person Register, CPR, has covered everyone living or formerly living in Denmark since 1968 [4]. It holds about 11 million people, including the dead and those who have emigrated [5]. Each person has a ten-digit number, the first six digits being the birth date, which “må ikke bruges som eneste dokumentation for en persons identitet” (TSN’s translation: “must not be used as the sole proof of a person’s identity”) [4].

What the authorities say

Confirmed (ministry, 5 October). Using a private firm’s lawful access, unauthorised people obtained names, addresses and CPR numbers for about 8.8 million registered people, living, dead and emigrated. The ministry says the figure may be revised and it cannot say who is behind it [3]. Its advice: never give out passwords or confidential information in calls or emails, even if the caller knows your name, address and CPR number [3]. At a press conference an official described the “harvest” as ten days in September, with well over 14 million lookups attempted, per TV 2 [2].

What is reported

Reported (Politiken). Headline: “Fynsk virksomhed havde mindst tre profiler med adgangskoden ‘123456’” (TSN’s translation: “Funen company had at least three profiles with the password ‘123456’”) [6]. The Copenhagen Post, relaying Ritzau, says one was an administrator account [7]. Politiken’s article is paywalled; TSN could read only its headline and standfirst. TV 2 says Politiken’s earlier account, that the intruder entered Pays’ account after an email with that password appeared in a larger data leak, “matches TV 2’s research” [1].

Reported (TV 2). Documents TV 2 obtained under freedom-of-information rules show access from 10 September for 21 days and 17 hours in total; the activity apparently stopped on 20 September, 12 days before it was noticed on 2 October [2]. Politiken and the Copenhagen Post repeat the 21-day figure without naming a source [6][7].

An anonymous person told Politiken they carried out the attack; TV 2 says it could not verify their identity or statements [2]. TSN does not repeat their other claims.

What this does not show

  • That the weak password was the route in. That is Politiken’s report, matched by TV 2; authorities have not said.
  • Who did it. Police say they have no indication of who is behind it, and nobody is charged [2].

The Bottom Line

Pays ApS confirms its lawful register access was abused, and the ministry puts the exposure at about 8.8 million people. The “123456” detail and the 21-day access window are reported, not officially confirmed.

Related on TSN: Cyber Breaches: SoftBank Cloud Ransomware, Qilin’s 53 Japanese Victims, Asos’s Bigger Leak and Denmark’s Register

Sources

  1. Mikkel Walentin Mortensen, “Her er den fynske virksomhed cpr-lækket gik igennem” (Here is the Funen company the CPR leak went through), TV 2, 9 October 2026, 15:38 Danish time (in Danish; TSN’s translation; Pays’ emailed statement). https://nyheder.tv2.dk/business/2026-10-09-her-er-den-fynske-virksomhed-cpr-laekket-gik-igennem
  2. TV 2 live blog, “Cpr-lækket gik igennem den fynske virksomhed Pays ApS” (in Danish; TSN’s translation; entries including the freedom-of-information documents, 9 October 2026, and the ministry press conference). https://nyheder.tv2.dk/live/samfund/2026-10-05-uvedkommende-har-faaet-adgang-til-88-millioner-cpr-numre
  3. Forsknings-, Uddannelses- og Digitaliseringsministeriet, “Omfattende uautoriseret adgang til borgeres CPR-oplysninger” (Extensive unauthorised access to citizens’ CPR information), 5 October 2026 (ministry press release, in Danish; TSN’s translation). https://fudm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/
  4. Borger.dk, “Det Centrale Personregister (CPR)”, read 10 October 2026 (official Danish citizen portal; in Danish; TSN’s translation). https://www.borger.dk/samfund-og-rettigheder/Folkeregister-og-CPR/Det-Centrale-Personregister-CPR
  5. CPR-administrationen, “Hvad og hvem er registreret i CPR” (What and who is registered in CPR), read 10 October 2026 (official; in Danish). https://www.cpr.dk/borgere/hvad-staar-der-om-mig-i-cpr-registerindsigt/hvad-og-hvem-er-registreret-i-cpr-og-hvem-opdaterer-oplysninger-om-dig-i-cpr
  6. Jonas Pröschold, Sebastian Stryhn Kjeldtoft and Magnus Bredsdorff, “»Oh my god«: Fynsk virksomhed havde mindst tre profiler med adgangskoden ‘123456’”, Politiken, 9 October 2026, 18:34 Danish time (in Danish; paywalled: only headline and standfirst read). https://politiken.dk/danmark/art11016363/%C2%BBOh-my-god%C2%AB-Fynsk-virksomhed-havde-mindst-tre-profiler-med-adgangskoden-123456
  7. Ritzau, “‘123456’ password used in massive Danish CPR data breach”, The Copenhagen Post, 10 October 2026 (relays Politiken and TV 2). https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.