Sweden fines Miljödata $183,000 over breach affecting 2.2 million

· Original article ↗

Summary

Sweden’s privacy regulator IMY fined IT systems provider Miljödata SEK 1.8 million ($183,000) after finding inadequate security measures contributed to an August 2025 cyberattack that affected 2.2 million people. The breach disrupted IT services in more than 200 regions and exposed sensitive personal and HR-related data; stolen data was reportedly published on the dark web after a ransom demand was not met.

Key points

  • IMY imposed a SEK 1.8 million ($183,000) penalty on Miljödata for violating GDPR Article 32(1).
  • The August 25, 2025 cyberattack disrupted IT services in more than 200 regions and affected 2.2 million people.
  • Compromised information included personal identity numbers, contact details, sickness absence, rehabilitation information, and school incidents involving minors.
  • According to the article, the threat actor demanded 1.5 Bitcoin, valued at $168,000 at the time, and later published stolen information on the dark web under the name “Datacarry.”
  • IMY found that Miljödata did not sufficiently check newly installed software and lacked automated real-time monitoring to identify intrusions and suspicious activity.
  • IMY has also opened ongoing investigations into two municipalities and one region in connection with the Miljödata attack; further penalties may be imposed.

Tags

Data BreachSensitive Personal DataGDPRRegulatory FineRansomware ExtortionThird-Party Risk

Threat Actors

Vendors

Countries

Industries