Sweden fines Miljödata $183,000 over breach affecting 2.2 million
In August 2025, Swedish IT systems provider Miljödata suffered a cyberattack that compromised sensitive personal data of 2.2 million individuals across over 200 regions. The attacker demanded a ransom and subsequently published the stolen data on the dark web. The Swedish data privacy regulator IMY fined Miljödata $183,000 for inadequate security measures, including insufficient software checks and lack of automated real-time monitoring, violating GDPR Article 32(1). Investigations into related municipalities and regions are ongoing.
AI Analysis
Technical Summary
Miljödata, a Swedish software company serving 80% of Sweden's municipal systems, experienced a cyberattack in August 2025 that disrupted IT services and exposed sensitive personal data of 2.2 million people. The threat actor demanded 1.5 Bitcoin ransom and leaked the data under the alias 'Datacarry'. IMY's investigation found Miljödata failed to maintain adequate technical and organizational security, specifically lacking sufficient checks on newly installed software and automated real-time intrusion detection. This constituted a violation of GDPR Article 32(1), resulting in a $183,000 fine. Additional investigations into affected municipalities and regions are ongoing.
Potential Impact
The breach exposed sensitive personal data including identity numbers, contact information, health-related data, and school incident records involving minors. The data leak affected 2.2 million individuals and disrupted IT services in over 200 regions. The exposure of such data poses significant privacy risks and potential harm to affected individuals. The incident also led to regulatory penalties under GDPR for Miljödata and may result in further fines for related entities.
Mitigation Recommendations
The vendor was fined for failing to implement adequate security measures, specifically insufficient software installation checks and lack of automated real-time monitoring. Organizations should ensure rigorous validation of software installations and deploy automated, real-time intrusion detection systems to comply with GDPR Article 32(1). Since this is a past incident with regulatory action taken, no urgent remediation is indicated beyond adherence to GDPR security requirements. Ongoing investigations may inform further mitigation steps.
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Description
In August 2025, Swedish IT systems provider Miljödata suffered a cyberattack that compromised sensitive personal data of 2.2 million individuals across over 200 regions. The attacker demanded a ransom and subsequently published the stolen data on the dark web. The Swedish data privacy regulator IMY fined Miljödata $183,000 for inadequate security measures, including insufficient software checks and lack of automated real-time monitoring, violating GDPR Article 32(1). Investigations into related municipalities and regions are ongoing.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Miljödata, a Swedish software company serving 80% of Sweden's municipal systems, experienced a cyberattack in August 2025 that disrupted IT services and exposed sensitive personal data of 2.2 million people. The threat actor demanded 1.5 Bitcoin ransom and leaked the data under the alias 'Datacarry'. IMY's investigation found Miljödata failed to maintain adequate technical and organizational security, specifically lacking sufficient checks on newly installed software and automated real-time intrusion detection. This constituted a violation of GDPR Article 32(1), resulting in a $183,000 fine. Additional investigations into affected municipalities and regions are ongoing.
Potential Impact
The breach exposed sensitive personal data including identity numbers, contact information, health-related data, and school incident records involving minors. The data leak affected 2.2 million individuals and disrupted IT services in over 200 regions. The exposure of such data poses significant privacy risks and potential harm to affected individuals. The incident also led to regulatory penalties under GDPR for Miljödata and may result in further fines for related entities.
Defensive Guidance
The vendor was fined for failing to implement adequate security measures, specifically insufficient software installation checks and lack of automated real-time monitoring. Organizations should ensure rigorous validation of software installations and deploy automated, real-time intrusion detection systems to comply with GDPR Article 32(1). Since this is a past incident with regulatory action taken, no urgent remediation is indicated beyond adherence to GDPR security requirements. Ongoing investigations may inform further mitigation steps.
Technical Details
- Classification
- {"confidence":0.83,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/","fetched":true,"fetchedAt":"2026-09-22T22:02:47.654Z","wordCount":651}
Threat ID: 6ab2fb07f7a7c54106d67607
Added to database: 09/22/2026, 22:02:47 UTC
Last enriched: 09/22/2026, 22:02:58 UTC
Last updated: 09/23/2026, 03:46:33 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.