Hacker broke into CPR register with password 123456 and obtained 8.8 million numbers

An anonymous hacker claims to have obtained nearly 8.8 million Danish CPR numbers via a leaked, simple password. The minister acknowledges insufficient security.

Hacker broke into CPR register with password 123456 and obtained 8.8 million numbers

Leaked access code gave access to nearly all of Denmark's CPR register

An anonymous hacker claims to Politiken to be behind the breach of the Danish CPR register on 11 September this year — and that access was obtained via the password 123456.

According to B.T., it has not until now been publicly known who gained access to the register and thereby obtained access to information about nearly 8.8 million Danes.

The hacker explains that the access code came from a former employee at a smaller Danish company with legitimate access to the CPR register. With the leaked code, the person constructed two computer programmes which found and stored the CPR information externally.

"Really shocked" by the security

The hacker describes himself as "really shocked" by the inadequate security and uses the following comparison to Politiken:

> Someone leaves a suitcase with 10 kilos of plutonium unattended at a railway station. Then a homeless person steals it. Yes, of course one should not steal other people's suitcases. But neither should one leave nuclear material at a railway station.

The hacker states that he has no plans to sell or leak the CPR numbers. The interview took place in English via an encrypted service.

Expert finds the explanation credible

The hacker has shared a file containing the many CPR numbers with Politiken, which has passed it on to IT security expert Emil Hørning from Defend Denmark. Hørning assesses it as likely that the hacker is telling the truth, and that the described method has been used.

Minister acknowledges failure

Research, Education and Digitalisation Minister Christina Egelund (M) acknowledges in a written response that the security surrounding the CPR system has not been sufficient. She states that a halt has now been put to similar unauthorised access, and that she has commissioned a broader security review of the system.

Private companies and associations can today obtain access to the CPR register, for example for use in obtaining address information on customers or members.

Source: B.T.

Read this article in the original language