Denmark’s national health register fell to a password of 123456

Three weak contractor logins opened Denmark's CPR register and exposed 8.8 million health and identity records.

MedRisk Staff
By
2 Min Read

Three accounts at a small Danish IT contractor shared one of the weakest passwords in existence, and through them an intruder walked into the Central Person Register, the national database holding the health, address and identity records of the country’s residents.

Politiken reported that at least three user logins at the Funen-based firm Pays used “123456” to reach the CPR system, including the account reserved for administrators. An Aarhus University engineering professor called the setup hopeless, noting that simple string sits near the top of every common-password list.

The register notified authorities of odd activity in September and confirmed roughly 8.8 million people were exposed, both the living and the deceased. The intruder’s probable route was simpler still: a leaked credential tied to a former employee at the contractor, followed by two homemade programs built to pull records out and store them elsewhere. The register cut the company’s access, alerted the Danish Data Protection Agency and opened a police inquiry.

For healthcare defenders the lesson is unglamorous. Registers like the CPR feed identity checks, insurance and clinical coordination across a health system, and they only hold up if the vendors granted lookup rights guard their own doorways. One reused password at one supplier reached millions of records.

Share This Article