Prevalent themes in the discussion
-
Weak authentication practices – Many commenters pointed out the use of trivial passwords and missing multi‑factor authentication as the immediate cause of the leak.
“If your job title implies even a smidgen of security responsibility, you deserve to be fired for ‘123456’ as your password.” – giveaccountpls
-
Systemic misuse of the CPR number as a secret – The core problem is treating a public‑facing identifier as a confidential credential.
“Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong.” – ptnpzwqd
-
Privatization and cost‑driven outsourcing – The breach occurred at a tiny firm hired under a “cheapest offer” rule, highlighting how procurement policies undermine security.
“It was run by DXC Technology, the Danish branch of a US software house. When doing a contract on such programs the Danish government must take the cheapest offer by rule.” – LarsKrimi
-
Diffuse accountability and blame‑shifting – Participants noted a tendency to scapegoat individuals rather than fix organizational or systemic failures.
“Everyone is responsible… from the press… to the people who OKed the company for 3rd party access, to the team responsible for regulation…” – ionwake