Skip to main content
ComplianceData Protection

Sweden Fines Miljödata $183,000 for GDPR Breach Over Inadequate Security

Swedish government building with data storage device in foreground.

2.2 million people had personal records exposed after an August 2025 breach of Miljödata, Sweden’s widespread municipal HR and work-environment software provider.

What happened on August 25, 2025

On August 25, 2025, Miljödata suffered a cyberattack that disrupted IT services in over 200 regions and compromised residents' sensitive data. The company provides work environment and HR management systems used by 80% of Sweden’s municipal systems, making the incident large in both scale and reach.

Data stolen, ransom demand, and public disclosure

The stolen material—later published on the dark web under the name “Datacarry”—included personal identity numbers, contact information, sickness absence records, rehabilitation data, and school incidents involving underage individuals. The threat actor initially demanded a ransom of 1.5 Bitcoin, which the source records as valued at $168,000 at the time. When the ransom did not prevent publication, the data was released publicly on the dark web.

IMY investigation and findings: Article 32(1) violation

Sweden’s data privacy regulator, IMY, opened an investigation in November 2025 to determine whether Miljödata’s security shortcomings violated the European Union’s General Data Protection Regulation (GDPR). IMY has now confirmed the company failed to perform sufficient checks when installing new software and lacked automated, real-time monitoring of its systems to detect intrusions and suspicious activity. “IMY’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed,” reads the agency announcement.

IMY concluded that this negligence constituted a breach of Article 32(1) of the GDPR and imposed a penalty of $183,000 (SEK 1.8 million).

Ongoing probes into municipalities and potential further penalties

IMY also said it has launched investigations into two municipalities and one region in connection with the Miljödata attack. Those investigations are ongoing, and IMY warned that additional penalties may be imposed in the future depending on their outcomes.

What this means for technologists, municipalities, and the public

  • Technologists and security teams: The IMY findings single out two controllable failures—insufficient validation of newly installed software and lack of automated, real-time monitoring—underscoring where defensive controls were judged inadequate in this case.
  • Municipal procurement and administrators: The breach affected systems used by 80% of Sweden’s municipal systems and disrupted services across more than 200 regions, signaling that procurement actors who rely on third-party HR and work-environment platforms will be watched closely by regulators.
  • The public and affected individuals: Personal identity numbers, contact details, health-related records, and school-incident reports for underage people were among the exposed datasets; victims and local authorities are likely to face long tails of notification, remediation, and reputational consequences.

There is a sharp lesson threaded through these facts: the regulatory response focused less on the headline size of the breach and more on gaps in basic technical and organizational measures—software-validation and real-time monitoring—that IMY judged were inadequate given the sensitivity and scale of the data processed. IMY’s decision to pursue further probes of municipalities and a region means the full administrative and financial consequences are still unfolding; additional penalties could follow as those investigations conclude.

Original reporting: https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/