Skip To main content
defend Iceland

How I found all corporate usernames in Iceland

(This article was not written using AI)

One of my favorite methods to gain initial access to companies is finding valid credentials. If your target is just one employee, this might be near impossible. But what if you have hundreds, or even thousands of targets? What if the target victim is anyone in Iceland? Then gaining valid credentials goes from near impossible to near certain.

Ethical disclaimer

This article describes techniques for discovering social security numbers, usernames and testing login resilience for educational purposes only. I performed this work as an ethical security researcher. Do not use these methods to access systems you do not own or have explicit permission to test. If you find a vulnerability, report it responsibly.

1. How to discover the national registry

The first step is to download the national registry. You might think that is not possible because the national registry is not open to just anyone, and you are right, unless you are a hacker. Using the hacker mindset, you set out with the aim of obtaining a copy of the national registry.

There are a few ways to do that (other than downloading it from your place of work). Most start with locating an endpoint where you can enter a social security number for an individual, and the form you are using automatically displays the person’s full name. Think, for example, when you are transferring money to someone: you input their social security number in the recipient field and their name is automatically added to the name field.

Figure 1: An example of a real form open to anyone online which auto populates my name and full address. Unauthenticated.

If you proxy the traffic between your browser and the backend service you will probably see the request being sent and the response received. That request is usually not complicated. You can grab that request and try it in a command shell, and the chances are you will get the person’s name, and even full address, in raw JSON format.

Figure 2: The browser developer tools network response for a single lookup - JSON returning the matching person’s national ID, name, address, postal code and municipality.

I am going to go on a deep dive here, so if you are not interested in the technical details, feel free to skip to the next section. Just know that I can use this traffic to guess everyone’s kennitala and get their full name and, in some cases, home address according to the government, not the phonebook.

Deep dive into obtaining the national registry

On rare occasions you can even find an endpoint that accepts a name and returns a kennitala where you can type in a small subset of characters, for example “a” and you will get everyone that has “a” in their names. Then you can promptly proceed to download the entire national registry by going through the alphabet until you have everyone. That’s about 32 requests unless you include C and Z for good measure.

If you don’t find such a convenient endpoint, but you do find one that will accept any number of requests in quick succession then you can use that too. It’s just a little more work.

Create a script and just send all possible social security numbers in a loop and collect the responses. Easy as that.

This works because of a little quirk in how our social security numbers work. We have this thing called “vartala” which is a mathematical function that will tell you if a kennitala is valid or not. I am not going to go into details on how exactly that works, but, if you reverse engineer it, you can create every single possible kennitalas for all days of every year since the oldest person in Iceland was born. Or just, since 70 years ago to limit the scope to retirement age up until about 20 years ago to exclude young people. This is not complicated, just ask AI. It turns out that the maximum number of kennitalas you can have each day is ~72. Which means that theoretically, you can only have ~72 people in the registry born on the same day. (This is being addressed recently with the introduction of a “system social security number” which supposedly does not need to pass this check. It’s going to be a nightmare because most systems in Iceland implement this check and reject the social security numbers that fail).

This means that if we only want everyone who is of working age, between around 20 and 70, we only need to send 1.314.900 requests to the server to download everyone from the national registry. You might think that is a lot, but remember, we are using computers. Computers do this sort of thing for a living. And these are some of the most optimized endpoints in most systems because looking up someone in the corporate database is one of the most common and crucial tasks in most organizations. Some endpoints can return hundreds of results every second from their up-to-date national registry copy.

It is not a bad idea to use an endpoint that will allow you to remove the cookie and/or authorization header and see if it still works. Use a VPN for good measure, and you are as good as anonymous while you calmly proceed to extract the names and the legal residence of every Icelander dead or alive.

The reason this works is because of how we abuse the social security number system. In most other countries, your social security number is a secret that is not easily guessable. And even if you did, endpoints that will provide you with the person's name and address are even harder to find. Not impossible, but hard. And when they are found, they are classified as a major data breach.

2. Guessing everyone's username

Alright, but how do you get from there to guessing passwords? Companies do not use kennitalas for corporate logins, so all you have now is usernames that are often different from customer identifiers. That is not what we are interested in at the moment. Maybe in my next blog post.

Companies use various combinations of employee names for usernames. For example, my name is Guðmundur Karl Karlsson. My corporate email address is likely one of the following:

gudmundur@smelltuher.is
gudmundurk@smelltuher.is
gudmundurkk@smelltuher.is
gudmundur.k@smelltuher.is
gudmundur.k.k@smelltuher.is
gumdundur.karl.karlsson@smelltuher.is

You get the idea. The first thing I do is check if employees are listed on the company website. That makes things a lot easier. Some sites even include emails, and some use “(hja)” instead of “@,” which does not slow me down.

But I am interested in every company in Iceland. Fortunately, most companies have stopped advertising employee details on their site. Now I already know most people’s names in Iceland because I have a copy of the national registry. All I need to do is figure out which username style the company uses for logins.

Often the email is the full name, while the login name is a shorter version. This might be as easy as Googling a couple of employees, and it is almost guaranteed that some people use their login name as their email. In some cases I have gone through document metadata to find “Created by.” The point is, it is easy. I compile a list of every possible email the company might use, using every name from the registry. That gives a few hundred thousand possible email combinations for all working-age people in Iceland.

Enter Microsoft

Again, I am going to go on a bit of a deep dive here and explain exactly how I get the usernames. If you are not interested in the technical aspect, feel free to skip to the next section.

Just know that using what I have so far, I can use a OneDrive feature to get login emails of everyone who works at a company. A common tool in a hacker’s arsenal is a fuzzer. A tool that quickly runs through a list of queries and reports responses including headers and HTTP status codes. OneDrive has an endpoint that accepts a company’s tenant name and a username and returns 403 (access denied) if you try to access an employee’s Documents folder, while it returns 404 if the folder does not exist.

Figure 3: Probing SharePoint personal OneDrive URLs with curl: a valid username returns 403 Forbidden while an invalid one returns 404 Not Found - separating real accounts from non-existent ones.

I construct a string with a placeholder for the potential username, then use FFUF to test that string against every potential username. Going relatively slow on a VPN, so I don’t annoy Microsoft or get blocked on my home network, I can enumerate every valid username on the company network in about an hour or two, simply because valid users return 403 while invalid ones return 404.

An example ffuf command I used for this purpose was:

ffuf -w firstnamem.txt -u https://healthis-my.sharepoint.com/personal/FUZZ/_layouts/15/onedrive.aspx -t10 -mc 401,403,200

In this case, firstnamem.txt contains all possible combinations of a person’s first name and middle initial.

Figure 4: A generated username wordlist (firstnamem.txt) of candidate accounts for the target domain - here over 3.7 million entries.

3. How do I get the passwords

As I mentioned before, I do not need everyone’s password, I just need one. The odds are at least one person is using a weak, predictable password like Sumar2025. I use a tool called trevorspray to systematically test a small number of passwords (usually 5–10, depending on the company’s lockout policy) against many users.

I will not go into deep technical details about how that tool works, because it is documented elsewhere. To avoid getting flagged by Microsoft or a firewall I use an API gateway hosted on Amazon. That makes each request appear to come from a unique IP address, which can bypass naive rate limiters bound to the attacker’s IP address. The gateway forwards requests to the company’s tenant /oauth2/token endpoint using the company’s tenant ID.

Figure 5: The public whatismytenantid.com lookup revealing the Microsoft 365 tenant ID for landspitali.is.
Figure 6: A successful attack using Trevorspray. This specific user changed their password from Sumar2025. To Haust2025. Just a few weeks later. (Not on Landspitali)

I run these procedures seasonally, about four times a year. After 5–10 failed attempts users typically get locked out until they reset their password after a valid login. Many companies implement smart lockout features so the user may not notice, because logins can still succeed from known IPs, the company VPN, or on-site networks.

I leave users 2–3 attempts in my testing because I practice ethical hacking, and I am not trying to cause unnecessary pain. I am trying to get valid credentials so I can find a vulnerable system to exploit and responsibly report to the bug bounty program Defend Iceland, and hopefully receive a small reward for the effort. The odds are, if I were not an ethical hacker, this initial access could be all that stands between a company and a major data breach.

4. How do we protect ourselves

We messed up. We have to start protecting the national registry. We must protect users by securing seemingly innocent endpoints. Such endpoints are now common. You can barely register on a pizza app without the UI looking up your name on the backend using your social security number, which can then be abused to look up a victim’s legal residence.

We owe this to our users and to everyone in Iceland. Corporate networks often depend on these same registries, as I hope I demonstrated in this post. It goes without saying that every application we use must have multi-factor authentication enabled by default. This includes third-party apps for employee timecards, staff union holiday pages, and everything employees, customers, and vendors touch for personal or work reasons.

Most major breaches start with a single user’s compromised credentials. Often that compromise is even easier than what I described, because the credentials usually just come from data breaches published online.

Deila

Aðrar fréttir

Sjá allar fréttir
Is Your CTO Vibe-Coding?

Is Your CTO Vibe-Coding?

Most of the conversation about AI and security runs in one direction: the barrier to entry for attackers is collapsing. A teenager with a chatbot can now scan, probe, and exploit at a level that used to require years of practice. That's a real problem, and it deserves the attention it gets.

Lesa meira
Landspítali

Multiple Landspitali Employee Domain Accounts at Risk of Compromise

This report details a critical security vulnerability discovered within Landspitalinn's systems through the Defend Iceland bounty program. A series of chained vulnerabilities and misconfigurations were identified, allowing attackers to compromise multiple employee credentials and register multi-factor authentication (MFA) to themselves.

Lesa meira
Public disclosure for a healthier cybersecurity culture

Public disclosure for a healthier cybersecurity culture

Landspitali is the leading hospital in Iceland and the largest workplace for employees in health care. It is funded by the Ministry of Welfare, supervised by the Directorate of Health and provides specialised and general care and has the capacity of approx. 700 beds. To say that it is an important organisation in Iceland is an understatement and almost every Icelander relies on their services in some way.

Lesa meira
When Retired Domains Come Back to Haunt: The Hidden Risk of Legacy Corporate Assets

When Retired Domains Come Back to Haunt: The Hidden Risk of Legacy Corporate Assets

Organizations evolve through mergers, acquisitions, and rebranding. Old domains get retired, but what happens when those domains can still receive password resets or act as the login email for third-party services for the previous owner? This post reveals an overlooked vulnerability we've seen through Defend Iceland's bug bounty platform: expired corporate domains that remain deeply embedded in third-party SaaS accounts. When these domains become available for registration, attackers can inherit access to SaaS accounts that still use the retired email domain for login or recovery. We'll show you exactly how this happens and why "just let it expire" is a dangerous domain retirement strategy.

Lesa meira
XSS Beyond the Perimeter: When Internal Systems Become Attack Surfaces

XSS Beyond the Perimeter: When Internal Systems Become Attack Surfaces

Cross-site scripting (XSS) is often treated as a problem that ends at the public perimeter. In reality, customer input does not stop at the landing page. It flows into CRMs, ticketing consoles, and internal dashboards that may never have faced a penetration test. This walkthrough, based on real reports to Defend Iceland, shows how a harmless contact form can compromise the helpdesk staff who read it. To illustrate the chain end to end, we built a Netbankinn-themed lab that mirrors what we see in production environments. The public site is squeaky clean. The internal system is not, and an ezXSS payload turns one support ticket into full access to the staff's browser context.

Lesa meira
Hvernig villuveiðigáttir hjálpa þér að uppfylla NIS2

Hvernig villuveiðigáttir hjálpa þér að uppfylla NIS2

Ný tilskipun Evrópusambandsins um net- og upplýsingaöryggi, NIS2, er yfirvofandi og gerir auknar kröfur til mikilvægra og nauðsynlegra aðila um netöryggi, áhættustýringu og upplýsingagjöf. Fyrirtæki sem falla undir tilskipunina þurfa nú að sýna fram á aukna öryggisvitund, skilvirkari viðbragðsáætlanir og betri stjórn á veikleikum. Ein skynsamleg og hagkvæm leið til að ná þessum markmiðum er með villuveiðigáttum og stefnu um ábyrga upplýsingagjöf öryggisveikleika (e. coordinated vulnerability disclosure).

Lesa meira
404 Villa Happy Hour Fannst ekki!

404 Villa Happy Hour Fannst ekki!

Defend Iceland býður í Happy Hour með netöryggis- og varnarmála ívafi í samstarfi við miðstöð stafrænnar nýsköpunar (EDIH-IS) og Rannís. Viðburðurinn er opinn öllum sem hafa áhuga en skráning er nauðsynleg.

Lesa meira
Guðmundur Fertram fjárfestir í Defend Iceland

Guðmundur Fertram fjárfestir í Defend Iceland

Við hjá Defend Iceland erum stolt af því að tilkynna nýja fjárfestingu frá fjárfestingafélagi í eigu Guðmundar Fertrams Sigurjónssonar, stofnanda Kerecis, og fjölskyldu hans. Með þessari fjárfestingu styðja þau við framtíðarsýn okkar um öruggara stafrænt samfélag með þróun á villuveiðigátt okkar og öðrum lausnum. Ísland er fyrsti markaðurinn þar sem þessi tækni verður sannreynd og prófuð í raunumhverfi.

Lesa meira
Jason Haddix, forstjóri Arcanum Security

Einn færasti hakkari heims heldur námskeið á Íslandi í öryggisveikleika leit (e. Vulnerability hunting)

Jason Haddix, einn færasti hakkari heims og forstjóri Arcanum Security, er væntanlegur til landsins í næstu viku og mun leiða námskeið í öryggisveikleika leit í samstarfi við Defend Iceland dagana 21. - 23. janúar í Háskólanum í Reykjavík. Jason kemur frá Bandaríkjunum og er með yfir 20 ára reynslu í netöryggi auk þess hefur hann hlotið viðurkenningu sem einn af fremstu sérfræðingum á villuveiðigáttum (Bug Bounty Platform). Alþjóðleg fyrirtæki á borð við Apple, Microsoft, Google, KPMG, Deloitte, Amazon, Walmart og fleiri hafa reglulega nýtt sér námskeið og þekkingu Jason Haddix.

Lesa meira
Spennandi áfangi hjá Defend Iceland

Spennandi áfangi hjá Defend Iceland

Við fórum í loftið í febrúar á þessu ári og erum stolt af því að vera komin í samstarf við 26 frábæra viðskiptavini. Þessir aðilar spanna öll svið samfélagsins, frá stórum hluta fjármálageirans til lykilaðila í orku- og heilbrigðisgeiranum - og nú Alþingi Íslendinga.

Lesa meira
Defend Iceland gerir samning við Origo til að efla netöryggi

Defend Iceland gerir samning við Origo til að efla netöryggi

Í samtengdu stafrænu landslagi nútímans hefur öryggi hugbúnaðar eins fyrirtækis áhrif á alla. Nýlegt atvik CrowdStrike og „bláskjár dauðans“ - sem leiddi til lokunar flugvalla um allan heim - eru áminningar um hvernig jafnvel einn öryggisveikleiki getur komið af stað keðjuverkun með gríðarlegum afleiðingum.

Lesa meira
Erindi Tedda á netöryggisráðstefnu Fjarskiptastofu

Erindi Tedda á netöryggisráðstefnu Fjarskiptastofu

Í dag var Fjarskiptastofa/ECOI með netöryggisráðstefnu þar sem Theódór Ragnar Gíslason, framkvæmdastjóri okkar og stofnandi, var með erindi þar sem hann varpaði fram eftirfarandi spurningu: Erum við einum veikleika frá game over? Hvaða veikleiki væri svo krítískur á birgðahliðinni að það hefði gríðarleg áhrif ekki aðeins á fyrirtækið þitt heldur líka á samfélagið okkar?

Lesa meira
Pallborð á málþingi Rannís - Vegferð styrkjaumsókna og ráð frá þátttakendum

Pallborð á málþingi Rannís - Vegferð styrkjaumsókna og ráð frá þátttakendum

Hörn Valdimarsdóttir frá Defend Iceland sat í pallborði á málþingi Rannís á dögunum þar sem umræðuefnið var „Vegferð styrkjaumsókna og ráð frá þátttakendum”. Málþingið var einskonar stöðutaka á árangri Íslands á fyrstu þremur árum rammaáætlunar og vettvangur þar sem þátttakendur og mögulegir umsækjendur um rammáætlanir gátu borið saman bækur sínar og kynnst. Styrkurinn sem við fengum frá Rannís hefur sannarlega gert vegferð okkar auðveldari og er meðal þess sem varð til þess að hugmyndin um öruggara stafrænt Ísland gat orðið að veruleika!

Lesa meira
DrupalCon Europe 2024

DrupalCon Europe 2024

Við erum spennt að segja frá því að stofnandi okkar og framkvæmdastjóri, Theódór Ragnar Gíslason, flutti hvetjandi erindi á hinni virtu ráðstefnu, DrupalCon Europe sem haldin var í Barcelona í ár. Þar lagði Teddi áherslu á framtíðarsýn og vegferð Defend Iceland! Vegferðin frá því að vera ungur hakkari yfir í að stofna netöryggisfyrirtæki eins og Syndis og Defend Iceland var ekki alltaf auðveld! Kærar þakkir til Baddy Sonja Breidert og flotta teymisins hjá 1xINTERNET fyrir ómetanlegan stuðning.

Lesa meira
Defend Iceland og Stafrænt Ísland í samstarf um netöryggi

Defend Iceland og Stafrænt Ísland í samstarf um netöryggi

Stafrænt Ísland og Defend Iceland hafa skrifað undir samning um samstarf á sviði netöryggis. Tilgangur samningsins er að nýta villuveiðigátt Defend Iceland til að finna öryggisveikleika í kerfum Stafræns Íslands og auka þannig og styrkja varnir gegn netárásum.

Lesa meira
Segir afsökun Microsoft lélega

Segir afsökun Microsoft lélega

„Persónulega finnst mér þetta léleg afsökun,“ segir Theodór R. Gíslason, stofnandi Defend Iceland, þar sem hann gagnrýnir Microsoft vegna viðbragða fyrirtækisins við öryggisbilun sem olli stórfelldri truflun á föstudaginn.

Lesa meira
Hjörtur Pálmi Pálsson

Stýrir uppbyggingu samfélags netöryggissérfræðinga

Hjörtur Pálmi Pálsson hefur gengið til liðs við Defend Iceland og mun hann stýra uppbyggingu samfélags netöryggissérfræðinga fyrirtækisins auk þess að leiða greiningu og úrvinnslu þeirra öryggisveikleika sem finnast hjá viðskiptavinum Defend Iceland. Greint er frá ráðningu hans í fréttatilkynningu.

Lesa meira
Skagi og Defend Iceland í samstarfi

Skagi og Defend Iceland í samstarfi

Skagi og Defend Iceland hafa gert samning um aðgang að hugbúnaði villuveiðigáttar fyrirtækisins til að fyrirbyggja árásir á net- og tölvukerfi Skaga, en í samstæðu Skaga eru VÍS, Fossar fjárfestingarbanki og SIV eignastýring.

Lesa meira
Brimborg og Defend Iceland í samstarf um netöryggi

Brimborg og Defend Iceland í samstarf um netöryggi

Brimborg hefur samið við netöryggisfyrirtækið Defend Iceland um aðgang að villuveiðigátt fyrirtækisins til að styrkja enn frekar varnir félagsins gagnvart netárásum, afla þekkingar á veikleikum tölvukerfa þess og miðla til eflingar netöryggis á Íslandi. Í samningnum felst að öryggissérfræðingar Defend Iceland munu nýta forvirkar öryggisaðgerðir til að leita að öryggisveikleikum, með því að herma aðferðir netárásarhópa og tölvuþrjóta, og tryggja þannig að hægt sé að laga veikleikana áður en þeir verða notaðir til netinnbrota.

Lesa meira
Gætu þurft að líta á netárásir sem hernað

Gætu þurft að líta á netárásir sem hernað

Netárásum hefur fjölgað verulega á Íslandi eftir að Rússar réðust inn í Úkraínu í febrúar 2022. Líklegt þykir að netþrjótarnir sem réðust á kerfi Árvakurs í gær tengist rússneskum glæpasamtökum – og jafnvel Kreml.

Lesa meira
Höfuðstöðvar Morgunblaðsins

Þetta er hópurinn sem gerði árás á Morgunblaðið

Rússneski hakkarahópurinn Akira er sagður hafa staðið á bak við árás á tölvukerfi Morgunblaðsins með þeim afleiðingum að gríðarlegt magn gagna var tekið í gíslingu. Vegna þessa lá fréttavefur Morgunblaðsins niðri í um þrjár klukkustundir og útsendingar K100 lágu niðri.

Lesa meira
Kóði og Defend Iceland í samstarf

Kóði og Defend Iceland í samstarf

Kóði og netöryggisfyrirtækið Defend Iceland hafa gert samning um aðgang að hugbúnaði villuveiðigáttar fyrirtækisins til að fyrirbyggja árásir á net- og tölvukerfi Kóða.

Lesa meira
Heiðarlegir hakkarar til varnar

Heiðarlegir hakkarar til varnar

Netöryggismál eru Theódóri Ragnari Gíslasyni hugleikin enda nauðsynlegt að huga að örygginu þegar viðkvæmar upplýsingar eru annars vegar. Fyrirtæki hans, Defend Iceland, aðstoðar fyrirtæki við að koma auga á veikleikana svo hægt sé að tryggja að ekki verði gerðar netárásir sem geta valdið miklum skaða eða viðkvæmum upplýsingum stolið. Theódór hyggst auka stafrænt öryggi Íslands og svo nýta þá reynslu víðar í hinum stóra heimi.

Lesa meira
Reiknistofa bankanna og Defend Iceland í samstarf

Reiknistofa bankanna og Defend Iceland í samstarf

Reiknistofa bankanna hefur samið við netöryggisfyrirtækið Defend Iceland um aðgang að hugbúnaði villuveiðigáttar fyrirtækisins. Með notkun villuveiðigáttarinnar nýtir Reiknistofa bankanna nýjustu aðferðir í netöryggi til að tryggja öryggi innviða fjármálakerfisins.

Lesa meira
Netöryggisfundur Defend Iceland

Netöryggisfundur Defend Iceland

Netöryggisfyrirtækið Defend Iceland, ásamt Rannís, Háskólanum í Reykjavík og Miðstöð stafrænnar nýsköpunar (EDIH-IS), hélt á dögunum hádegisfund í Grósku þar sem sjónum verður beint að forvirkum netöryggisráðstöfunum.

Lesa meira
Netárásir geta lamað samfélagið

Netárásir geta lamað samfélagið

Háskólinn í Reykjavík hefur enn ekki greitt lausnargjald fyrir gögn sem stolið var af rússneskum hakkarahópi í byrjun árs. Þrátt fyrir það hafa gögnin ekki verið birt. Lektor í tölvunarfræði segir þetta óvenjulegt fyrir hópinn en fleiri íslensk fyrirtæki hafi lent í því sama.

Lesa meira
Íslandsbanki semur um villuveiðigátt Defend Iceland

Íslandsbanki semur um villuveiðigátt Defend Iceland

Íslandsbanki er á meðal fyrstu fyrirtækja til að taka í notkun villuveiðigátt Defend Iceland, en í henni leiða saman krafta sína öryggissérfræðingar úr mörgum áttum og með ólíkan bakgrunn til að koma í veg fyrir alvarleg innbrot í net-, tölvu- og hugbúnaðarkerfi fyrirtækja og stofnana.

Lesa meira
Arion banki semur við Defend Iceland

Arion banki semur við Defend Iceland

Arion banki hefur gert samning við netöryggisfyrirtækið Defend Iceland um aðgang að hugbúnaði villuveiðigáttar fyrirtækisins. Í samningnum felst að öryggissérfræðingar Defend Iceland herma netárásir hakkara og árásarhópa í því skyni að finna veikleika í kerfum bankans svo hægt sé að lagfæra þá áður en þeir valda alvarlegum skaða.

Lesa meira
Fyrsta villuveiðigáttin fer vel af stað

Fyrsta villuveiðigáttin fer vel af stað

Íslensk fjármálafyrirtæki eru meðal þeirra sem taka þátt í villuveiðigátt Defend Iceland. Nú þegar hafa heiðarlegir hakkarar fengið greitt milljónir fyrir að benda á öryggisgalla og koma fyrirtækjum frá tilheyrandi tjóni.

Lesa meira
Tilkynna veikleika