Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems.
Last year, on August 25, the company suffered a cyberattack that disrupted IT services in over 200 regions and compromised residents' sensitive data.
The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information, but published it on the dark web under the name “Datacarry.”
The information included personal identity numbers, contact information, sickness absence, rehabilitation, and even school incidents involving underage individuals.
IMY launched an investigation in November 2025 to determine whether any security shortcomings violated the company’s obligations under the European Union’s General Data Protection Regulation (GDPR).
The agency has now confirmed that the company failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity.
“IMY’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed,” reads the announcement.
“The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity.”
The negligence constitutes a violation of Article 32(1) of the GDPR, for which the agency imposed a penalty of $183,000.
Threat actors sometimes use the prospect of regulatory penalties to pressure victims into paying, and may set demands below what they believe an incident would ultimately cost, to incentivize victims to pay the ransom.
IMY noted that it has also launched investigations into two municipalities and one region in connection with the attack on Miljödata, which are ongoing, so additional penalties may be imposed in the future.
References in this story
- IT system supplier cyberattack impacts 200 municipalities in Sweden www.bleepingcomputer.com A cyberattack on Miljödata, an IT systems supplier for roughly 80% of Sweden's municipal systems, has caused accessibility problems in more than 200 regions of the country.
- Data breach at major Swedish software supplier impacts 1.5 million www.bleepingcomputer.com The Swedish Authority for Privacy Protection (IMY) is investigating a cyberattack on IT systems supplier Miljödata that exposed data belonging to 1.5 million people.
- Integritetsskyddsmyndigheten | IMY www.imy.se Vi arbetar för att skydda alla dina personuppgifter, till exempel om hälsa och ekonomi, så att de hanteras korrekt och inte hamnar i orätta händer.



