Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems.
Last year, on August 25, the company suffered a cyberattack that disrupted IT services in over 200 regions and compromised residents' sensitive data.
The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information, but published it on the dark web under the name “Datacarry.”
The information included personal identity numbers, contact information, sickness absence, rehabilitation, and even school incidents involving underage individuals.
IMY launched an investigation in November 2025 to determine whether any security shortcomings violated the company’s obligations under the European Union’s General Data Protection Regulation (GDPR).
The agency has now confirmed that the company failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity.
“IMY’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed,” reads the announcement.
“The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity.”
The negligence constitutes a violation of Article 32(1) of the GDPR, for which the agency imposed a penalty of $183,000.
Threat actors sometimes use the prospect of regulatory penalties to pressure victims into paying, and may set demands below what they believe an incident would ultimately cost, to incentivize victims to pay the ransom.
IMY noted that it has also launched investigations into two municipalities and one region in connection with the attack on Miljödata, which are ongoing, so additional penalties may be imposed in the future.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)