The breach by the hackers was through the legitimate login credentials of a local company in Denmark, initial findings suggest.