The hacker has shared a file containing more than 8.7 million so-called CPR numbers, Denmark’s equivalent of Swedish personal identity numbers, and described his method to Politiken.
Experts interviewed by Politiken consider it likely that the hacker was involved in the breach.
Access to the register is said to have been gained using a leaked password - in this case, “123456” - belonging to a former employee of a small Danish company.
The hacker says he does not want to sell or leak the numbers, but describes being shocked by the security flaws and compares the situation to someone stealing a suitcase of plutonium left unattended at a train station.
“Of course you shouldn’t steal other people’s suitcases. But you shouldn’t leave nuclear fuel at a train station either,” the hacker tells Politiken.





