Nasdaq First North Growth Market announcement no. 10/2026, Copenhagen, August 24, 2026
FastPassCorp A/S delivered ARR growth of 23.7% in the first half of 2026, with ARR increasing from DKK 8.8 million to DKK 10.9 million as at 30 June 2026. EBITDA improved by DKK 85 thousand, or 19%, to DKK 529 thousand from DKK 444 thousand, and EBIT improved by DKK 556 thousand.
In company announcement no. 9/2026 of 3 July 2026, the company upgraded its expectation for ARR growth in 2026 from 15-20% to 30-35% and its expectation for EBITDA for the 2026 financial year to DKK 3.5-4.5 million. Both expectations are confirmed, based on the results for the first half-year and on developments since the end of the period. Growth was driven primarily by FastPass IVM, with continued customer additions to the SSPR solution.
The Board of Directors has reviewed and approved the interim financial statements. The figures have not been audited or reviewed by the company's auditor.
The company's revenue and earnings are traditionally weighted towards the second half of the year, while costs are distributed more evenly. In 2025, H1 EBITDA was less than one fifth of the full-year result. The half-year figures should accordingly not be interpreted as half of the expected full-year performance.
This pattern is reinforced in 2026 by the establishment of the company's US cloud operation. The establishment costs, comprising incorporation, cloud infrastructure, initial operation and related items, were recognised in the first half-year. From 1 July 2026 the operation covers its running costs and contributes positively to earnings, while the first half-year carried the costs without the corresponding revenue.
Deferred income increased by DKK 772 thousand, reflecting invoicing for subsequent periods, which is recognised over the subscription term.
In the comparison with H1 2025, it should be noted that the result for that period included the one-off recognition of a deferred tax asset of DKK 6.6 million. This accounting item accounts for the substantial difference between the results after tax for the two periods.
Equity was further strengthened in the second half of 2025. In December 2025, shareholders exercised their option to convert debt into shares, adding DKK 2.9 million. This is reflected in equity at the beginning of 2026 and is therefore not included in the movements for the first half-year.
The Rule of 40, introduced in the 2025 annual report, is calculated on a full-year basis and will next be reported in the 2026 annual report.
The global cyber security market is characterised by a marked increase in both the complexity and the intensity of attacks. Threat actors are applying generative AI to make social engineering substantially more convincing, including deepfake voice fraud, in which a legitimate employee's voice is imitated in order to deceive the service desk or other support functions. Attacks are consequently no longer confined to conventional phishing campaigns, but increasingly target identity directly, through compromise of privileged credentials and the use of AI-generated content to circumvent established verification procedures.
The service desk has become a preferred point of entry precisely because it is the function authorised to make exceptions to standard controls. It can reset a password, register a new authentication device or restore access to a locked account.
The transition to passwordless authentication reinforces this exposure. As organisations move away from passwords and rely on the user's mobile phone or computer as the primary authentication factor, the device becomes a single point of failure. When a user replaces a device, leaves the phone at home or runs out of battery, self-service is unavailable and the user must contact the service desk. Passwordless authentication does not remove the identity verification requirement; it relocates it to the service desk, where it must be addressed by other means.
During the first half of 2026 an inverted variant of this attack pattern became materially more prominent. In January 2026, Google Mandiant documented threat activity in which attackers telephone employees while impersonating internal IT support, directing them to credential-harvesting sites that replicate the organisation's own login page in order to capture single sign-on credentials and multi-factor authentication codes. The activity is tracked under several clusters, including UNC6661 and UNC6671, and has in individual cases resulted in unauthorised access to enterprise identity platforms. Mandiant notes that the attacks do not exploit vulnerabilities in the affected vendors' products, but rely on the effectiveness of social engineering, and Google's published recommendations identify strengthened identity verification in help desk processes as a primary countermeasure.
This supports the relevance of the company's product direction. FastPass IVM already provides protective measures against this attack type, and the company is developing a dedicated add-on that enables the end user to verify the identity of the service desk agent, thereby closing the remaining verification gap in workforce identity verification.
Demand is typically triggered by a concrete event: an actual attack, an attempted attack, or a penetration test documenting the organisation's exposure to social engineering. Attack groups are at the same time adapting their methods, including varying the profile of the callers used, specifically in order to exploit the assumptions built into service desk verification routines.
This announcement contains forward-looking statements, including the company's expectations for ARR growth and EBITDA for 2026. Such statements are subject to risks and uncertainties, and actual results may differ materially. FastPassCorp A/S undertakes no obligation to update these statements beyond what is required under applicable rules.
The half-year report is attached and can also be found on the website www.fastpasscorp.com .
The company will publish its 2026 annual results on April 6, 2027.
Anders Meyer, CEO
Email: anders.meyer@fastpasscorp.com
Sales & Media Inquiries
Email: info@fastpasscorp.com
Website: www.fastpasscorp.com
HC Andersen Capital
Pernille F. Andersen
Mobile: (+45) 30 93 18 87
E-mail: ca@hcandersencapital.dk
FastPassCorp provides Workforce Identity Verification solutions that protect help desks from social engineering while improving productivity through automation and self-service password reset (SSPR). The company serves mid-size and large enterprises and managed service providers with cloud-based and on-premises solutions. FastPassCorp is headquartered in Denmark with operations in the United States and the United Kingdom and is listed on Nasdaq Copenhagen (FASTPC).