Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden Fines IT Firm $183,000 Over Massive Data Breach Affecting 2.2 Million People

A Swedish software company that provides work environment and HR management systems to municipal authorities has been slapped with a hefty fine of $183,000 for inadequate security measures that led to a massive data breach last year. The incident exposed sensitive information of over 2.2 million people, including personal identity numbers, contact details, and even records of school incidents involving minors.

Miljödata, the IT systems provider in question, offers its services to a whopping 80% of Sweden’s municipal systems. In August 2025, the company fell victim to a cyberattack that disrupted IT services in over 200 regions and compromised residents’ sensitive data. The threat actor behind the attack demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information. However, they eventually published it on the dark web under the name “Datacarry.”

An investigation by Sweden’s data privacy regulator, IMY, revealed that Miljödata failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity. This negligence constitutes a violation of Article 32(1) of the General Data Protection Regulation (GDPR), which mandates organizations to implement appropriate technical and organizational measures to ensure the security of personal data.

The fine imposed on Miljödata is not only a significant blow to the company’s finances but also a warning to other organizations handling sensitive information. The regulator has also launched investigations into two municipalities and one region in connection with the attack, which may result in additional penalties in the future.

This incident highlights the importance of robust security measures in protecting against cyber threats. Organizations must prioritize the implementation of automated monitoring systems and regular software updates to prevent similar breaches from occurring. Furthermore, they should be aware that threat actors often use the prospect of regulatory penalties to pressure victims into paying ransom demands.

In light of this case, it is essential for organizations handling sensitive information to reassess their security posture and implement measures to prevent data breaches. This includes conducting regular vulnerability assessments, training employees on cybersecurity best practices, and staying up-to-date with the latest threat intelligence. By taking proactive steps to strengthen their defenses, organizations can minimize the risk of cyberattacks and protect the sensitive information they hold.


Source: Bleeping Computer — 2026-09-22