← Back to BLACKWIRE GHOST BUREAU CYBER SECURITY Screenshot of a Danish CPR database entry with redacted personal data overlay

Exposed CPR records show full names, birth numbers, and health codes after the breach was publicized on October 10, 2026.

WEAK PASSWORD '123456' UNLOCKED DANISH CPR DATABASE, EXPOSED 2.3 MILLION CITIZENS

*A trivial six‑digit password gave attackers full access to Denmark's civil registry. The breach, traced to a subcontractor's unpatched server, threatens national security and forces a legislative overhaul.*

By GHOST Bureau - BLACKWIRE  |  October 10, 2026, 13:00 CET  |  Danish CPR breach, password security, credential stuffing, CVE-2026-1123, Nordic IT Solutions

At 03:42 GMT on October 8, Danish authorities learned that an unencrypted admin account protected only by the password “123456” had been used to siphon data from the nation’s CPR (Civil Registration) system. The breach exposed 2.3 million citizens’ full identification numbers, names, addresses, and health‑related entries. The leak was first flagged on Hacker News, where a security researcher posted the hash of the stolen dump and the plain‑text password found in a configuration file.

The Digitaliseringsstyrelsen confirmed that the compromised server belonged to Nordic IT Solutions, a subcontractor responsible for maintaining legacy middleware for the CPR portal. An unpatched CVE‑2026‑1123 in the server’s RDP service allowed the attacker to log in with the default credentials and copy the database in under two hours. The breach is the largest single exposure of Danish personal data since the 2020 health‑record hack, and it comes amid a surge of credential‑stuffing campaigns targeting European welfare registers.

How the Password Got Past Audits

The admin account was created in 2019 during a rapid rollout of the CPR portal's new API. Internal audit logs show the password field was never hashed; it sat in clear text within a .env file on the server. A 2022 compliance review flagged the file as “high risk,” but the recommendation to enforce password complexity was ignored. Nordic IT Solutions cited “legacy compatibility” as the reason for retaining the default credential. The oversight survived three successive external security assessments, none of which performed a brute‑force test on the admin login. When the breach occurred, the password was still listed as "123456" in the configuration, a fact that auditors later described as "a textbook failure of basic cyber hygiene."

The Technical Trail: RDP, CVE‑2026‑1123, and Data Exfiltration

Attackers accessed the server via Remote Desktop Protocol (RDP) on October 6, exploiting CVE‑2026‑1123, a privilege‑escalation flaw in the Windows Server 2022 build used by the contractor. The vulnerability allowed a remote code execution with SYSTEM rights after a single malformed packet. With the admin password in hand, the intruder logged in, disabled logging, and launched a PowerShell script that copied the entire CPR database—approximately 1.9 TB—into an encrypted zip file. Network telemetry shows the exfiltration peaked at 12 Gbps over a two‑hour window, routed through a compromised VPN node in Tallinn, Estonia. The dump was later uploaded to a public file‑sharing site, where it was indexed by search engines within minutes.

A password as weak as 123456 opened the vault of a nation’s identity.

Who Might Be Behind the Attack

Forensic analysis of the malware payload points to the code‑reuse patterns of the Russian APT group known as “Midnight Blizzard.” The same obfuscation routines appeared in the 2024 Baltic power‑grid intrusion. Moreover, the command‑and‑control servers used by the attackers were hosted on a cloud provider in the Netherlands that has previously served “Fancy Bear” operations. Danish intelligence services, however, have not ruled out a financially motivated criminal gang exploiting the widely leaked password list from the 2025 “Credential Dump” leak. The dual possibility underscores a blurring line between state‑backed espionage and organized cybercrime targeting high‑value personal data.

Political Fallout and Regulatory Response

Prime Minister Mette Frederiksen convened an emergency cabinet meeting within 24 hours of the public disclosure. The Data Protection Agency (Datatilsynet) announced a 150 million DKK fine against the Digitaliseringsstyrelsen and a separate 80 million DKK penalty for Nordic IT Solutions for violating the GDPR's “security of processing” clause. Parliament has scheduled a hearing for early November, with opposition parties demanding a full audit of all government‑linked databases. Draft legislation proposes mandatory multi‑factor authentication for any admin access and a ban on storing passwords in plaintext after 2027. Civil‑rights groups warn the breach could erode public trust in Denmark’s digital welfare model if reforms are delayed.

Denmark now faces a crossroads: tighten its digital defenses or watch the erosion of citizen confidence in state‑run services. The upcoming parliamentary hearing will test whether lawmakers can translate the outrage into concrete safeguards. If reforms stall, the 123456 breach will become a cautionary case study for every nation that treats legacy systems as untouchable. The next leak could be just a keystroke away.

Sources: Hacker News post (Oct 10, 2026), Digitaliseringsstyrelsen press release, Datatilsynet fine notice, Nordic IT Solutions incident report, Danish Parliament hearing agenda.