Expert gives CPR breach firm one out of 10 for security
Friday 9th October 2026 on 16:15 in
Denmark
A cybersecurity expert has rated a Funen company’s security one out of 10 after hackers exploited its access to Denmark’s civil registration system, DR reports. The breach involved access to 8.8 million personal identification numbers, known as CPR numbers.
DR reported that an employee’s password was “123456” and the company did not use two-factor verification. Peter Kruse, an IT security expert and Liberal Alliance councillor in Skanderborg Municipality, said the password could have been guessed in a very short time.
“It is a blatant breach of every good security practice,” Kruse said. “On a scale from one to 10, they get one for their security.”
The company, Pays, is based in Odense and had legal access to the CPR register. It confirmed to TV 2 that its access had been misused in an attack. Pays chief executive and owner Sophie Laursen said the company had been targeted.
DR also found a publicly accessible page on Pays’ website that appeared to be a tool for validating or cleaning CPR details, email addresses and postal addresses. Archived versions suggest the page was online as early as 2023, and it went offline late Thursday. Experts could not establish whether it had been used, or could have been used, to validate CPR details.
Kruse said the page should not have been openly searchable online, arguing that it could attract hackers by appearing to offer an easy way into the company’s systems.
He also criticised authorities’ monitoring and security requirements for companies with legal access to the CPR register. More than 13 million requests were made to the system in 10 days, he said, adding that there should be an automatic mechanism to stop such large-scale data extraction.
Kruse said a password for access to the CPR register must not be longer than eight digits, a requirement he described as outdated. Jacob Herbst, chair of the Danish Cyber Security Council, also said the case suggested authorities’ security rules and follow-up had not been adequate.
DR contacted Digitalisation Minister Christina Egelund for comment but had not received a response by publication. On Monday, the minister said there was “clearly” a security weakness in the CPR system.