Sweden Fines Miljödata $183,000 Over Breach Affecting 2.2 Million
Sweden Fines Miljödata $183,000 Over Breach Affecting 2.2 Million
Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems.
Last year, on August 25, the company suffered a cyberattack that disrupted IT services in over 200 regions and compromised residents’ sensitive data. The information included personal identity numbers, contact information, sickness absence, rehabilitation, and even school incidents involving underage individuals. The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information, but published it on the dark web under the name “Datacarry.”
IMY launched an investigation in November 2025 to determine whether any security shortcomings violated the company’s obligations under the European Union’s General Data Protection Regulation (GDPR). The agency has now confirmed that the company failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity. IMY’s announcement stated, “IMY’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed.”
The regulator further elaborated that “The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity.” This negligence constitutes a violation of Article 32(1) of the GDPR, leading to the imposed penalty of $183,000.
Threat actors sometimes use the prospect of regulatory penalties to pressure victims into paying and may set demands below what they believe an incident would ultimately cost to incentivize victims to pay the ransom. IMY noted that it has also launched investigations into two municipalities and one region in connection with the attack on Miljödata, which are ongoing, so additional penalties may be imposed in the future.