Sweden Fines IT Firm $183,000 for Breach Hitting 2.2 Million

Regulators found Miljödata lacked basic monitoring, exposing sensitive data of two million residents after a ransomware attack.
Key points
- Sweden's IMY fined Miljödata $183,000 for lacking real-time monitoring and software verification.
- The August 2025 breach exposed sensitive data of 2.2 million people, including health and school records.
- Investigators are also probing two municipalities and one region for their role in the incident.
Sweden’s data privacy authority has fined IT systems provider Miljödata $183,000 for failing to protect the personal information of 2.2 million people. The penalty follows a cyberattack in August 2025 that compromised sensitive records, including health data and school incident reports, after the company ignored basic security protocols.
The breach exposed a critical gap in how the company managed its infrastructure. According to the investigation, Miljödata did not adequately verify new software installations and lacked automated tools to detect suspicious activity in real-time. This negligence left the system vulnerable to the intrusion that ultimately disrupted services across more than 200 Swedish regions.
Regulators cite missing security checks
IMY, the Swedish data protection agency, determined that the company violated Article 32 of the GDPR by not maintaining a sufficient level of technical security. The agency highlighted that the absence of real-time monitoring meant attackers could operate without detection for a prolonged period. This finding underscores that even established providers can fall short of legal standards if they skip routine verification steps.
As reported by BleepingComputer, the threat actor initially demanded 1.5 Bitcoin, worth approximately $168,000 at the time, to prevent the data from being leaked. When the payment was not made, the attackers published the stolen information on the dark web under the name “Datacarry.” The released files contained personal identity numbers, contact details, and records of sickness absences and rehabilitation efforts.
Sensitive data exposed to public view
The scope of the leak included highly sensitive details about individuals, including underage students. The data contained information about school incidents, which raises significant concerns regarding the safety and privacy of children. For the affected residents, this means their most private life events and health statuses are now accessible to malicious actors on the open internet.
Miljödata provides work environment and HR management systems to 80% of Sweden’s municipalities. The breach therefore had a wide-reaching impact, affecting not just direct users but the broader administrative infrastructure that relies on these platforms. The disruption of IT services in over 200 regions highlighted how a single point of failure can cascade through public sector operations.
Further investigations target local municipalities
The regulatory action against Miljödata is not the end of the legal scrutiny. IMY has also launched investigations into two municipalities and one regional authority connected to the attack. These inquiries are currently ongoing, and additional penalties may be imposed if the authorities find that these local bodies also failed in their data protection duties.
This case illustrates the financial and reputational stakes of cybersecurity negligence. While the fine is a monetary penalty, the loss of public trust in a company serving 80% of the municipal sector may have a more lasting impact. The trade-off for companies that cut corners on monitoring is not just a fine, but the irreversible exposure of their clients' most private data.






