Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden’s Data Privacy Regulator Hits IT Firm with $183,000 Fine Over Breach Affecting 2.2 Million

The Swedish data privacy regulator, IMY, has issued a stern warning to IT systems provider Miljödata by slapping it with a hefty fine of $183,000 for its lax security measures that led to a massive breach last year. The attack compromised the sensitive information of an astonishing 2.2 million individuals, leaving many wondering how such a large-scale incident could have been prevented.

Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by a staggering 80% of Sweden’s municipal systems. In August 2025, the company fell victim to a cyberattack that disrupted IT services in over 200 regions and exposed residents’ personal data. The threat actor behind the attack demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information, which included sensitive details such as personal identity numbers, contact information, sickness absence records, rehabilitation data, and even school incidents involving underage individuals.

The breach raised concerns about the company’s security practices, with IMY launching an investigation in November 2025 to determine whether any security shortcomings violated the European Union’s General Data Protection Regulation (GDPR). The agency has now confirmed that Miljödata failed to adequately check newly installed software and lacked automated real-time monitoring mechanisms to detect intrusions and suspicious activity. This negligence constitutes a clear violation of Article 32(1) of the GDPR, for which the agency imposed a penalty of $183,000.

The incident highlights the importance of robust security measures in protecting sensitive data, particularly in industries that handle large amounts of personal information. It also underscores the need for companies to prioritize regular software updates and monitoring to prevent cyberattacks. Furthermore, it serves as a reminder that threat actors often use the prospect of regulatory penalties to pressure victims into paying ransoms, which can have devastating consequences.

The IMY’s investigation is ongoing, with the agency launching separate investigations into two municipalities and one region in connection with the attack on Miljödata. Additional penalties may be imposed in the future if any wrongdoing is found. As companies struggle to keep pace with evolving cyber threats, it is essential that they prioritize data protection and adhere to stringent security standards.

In light of this incident, organizations must take steps to ensure their security posture is robust and up-to-date. This includes implementing regular software updates, investing in advanced threat detection tools, and conducting thorough risk assessments to identify vulnerabilities. By taking proactive measures to protect sensitive data, companies can minimize the risk of breaches and avoid costly fines like Miljödata’s $183,000 penalty.


Source: Bleeping Computer — 2026-09-22