Hacker gained access to 8.8 million Danish CPR numbers using password "123456"

An anonymous hacker claims to have obtained nearly 8.8 million Danish CPR numbers through a small Danish company. A leaked password of just six digits reportedly made this possible.

Hacker gained access to 8.8 million Danish CPR numbers using password "123456"

Anonymous hacker claims massive CPR breach via weak password

An anonymous hacker claims to have gained access to nearly 8.8 million Danish CPR numbers after a simple password belonging to a former employee provided entry to the system. This is reported by The Copenhagen Post with reference to Politiken, which has spoken with the hacker.

The breach allegedly occurred on 11 September through a small Danish company with access to the CPR register. The password in question was reportedly "123456".

CPR numbers are the personal identification numbers Denmark uses in the Central Civil Register to identify citizens and provide access to public services.

The hacker told Politiken that after gaining access, the person developed two computer programmes to retrieve and store the CPR information outside the system. The individual's identity has not been made public, and the account has not been independently verified.

The hacker stressed that there are no plans to sell or publish the numbers, and described themselves as "really shocked" by the security vulnerabilities they encountered.

To illustrate the situation, the hacker used a comparison:

"Someone leaves a suitcase with 10 kilos of plutonium unattended at a train station. Then a homeless person steals it," said the hacker according to Politiken.

"Yes, of course one should not steal other people's suitcases. But one should also not leave nuclear material at a train station."

The hacker handed over a file containing the CPR numbers to Politiken, which passed it on to IT security expert Emil Hørning from Danish cyber security firm Defend Denmark. Hørning assessed that the hacker's account appeared credible, and that the described procedure was technically plausible.

Politiken conducted the interview with the hacker in English via an encrypted communication service.

Source: The Copenhagen Post

Read this article in the original language