Sweden Fines Miljödata $183,000 After Data Breach Exposed 2.2 Million People
Sweden’s data protection regulator, the Swedish Authority for Privacy Protection (IMY), has fined IT systems provider Miljödata $183,000 (SEK 1.8 million) for inadequate security measures that contributed to a data breach affecting 2.2 million people in August 2025.
Miljödata develops and provides work environment and human resources management systems used by 80% of Sweden’s municipal systems.
Miljödata cyberattack exposed sensitive personal data
On August 25, 2025, Miljödata suffered a cyberattack that disrupted IT services in more than 200 regions and compromised residents’ sensitive information.
The attackers demanded a ransom of 1.5 Bitcoin, worth approximately $168,000 at the time, to prevent the stolen data from being leaked. The information was later published on the dark web under the name “Datacarry.”
The exposed data included personal identification numbers, contact information, sick leave and rehabilitation records, as well as school incidents involving minors.
IMY found GDPR security violations
IMY launched an investigation in November 2025 to determine whether Miljödata’s security practices violated its obligations under the European Union’s General Data Protection Regulation (GDPR).
The investigation found that Miljödata did not properly check newly installed software and lacked automated, real-time monitoring to detect intrusions or suspicious activity.
“IMY’s investigation found that the company did not maintain a sufficiently high level of technical and organizational security given the type of personal data it processed.”
IMY also stated:
“The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions or suspicious activity.”
The shortcomings constituted a violation of Article 32(1) of the GDPR, which requires organizations to implement appropriate technical and organizational measures to protect personal data. IMY imposed a fine of $183,000.
More investigations could lead to additional penalties
Attackers may use the threat of regulatory penalties to pressure victims into paying a ransom. They may also set ransom demands below the costs they believe a victim will ultimately face, making payment appear more attractive.
IMY said it has also opened investigations into two municipalities and one region in connection with the attack on Miljödata. Those investigations are ongoing, and additional penalties may be imposed in the future.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



