Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 24, 2026 · 6 min read

Sweden Fines Miljödata SEK 1.8M Over 2.2M Person Breach

On September 22, 2026, Sweden's data protection authority IMY penalized the Karlskrona software vendor behind most of the country's municipal HR systems for the August 2025 ransomware attack. The fine is barely larger than the ransom the attackers asked for.

A week. That is roughly how long an outdated third party firewall component sat inside Miljödata's environment before attackers walked through it in August 2025. The vulnerabilities in that component were already listed on the supplier's own website. Thirteen months later, Sweden's Integritetsskyddsmyndigheten (IMY) put a price on the oversight: SEK 1.8 million, for a breach that exposed personal data on 2.2 million people, about a fifth of the country.

Key Takeaways

  • IMY fined Miljödata i Karlskrona AB SEK 1.8 million (about $183,000) on September 22, 2026 for violating GDPR Article 32(1), according to IMY's announcement.
  • The August 25, 2025 attack exposed personal identity numbers, contact details, sickness absence and rehabilitation records, and school incident reports involving minors for 2.2 million people.
  • IMY found two specific gaps: inadequate controls over software installations and no automated real time monitoring to detect intrusions.
  • IMY is still investigating two municipalities and one region that used Miljödata, so the customers of the vendor may face their own decisions.
  • At roughly SEK 0.82 per affected person, the penalty is modest, but it establishes that a processor can be fined directly for security failures that hit its public sector clients.

What Did IMY Fine Miljödata For?

IMY fined Miljödata for failing to maintain "a sufficiently high level of technical and organizational security" given the kinds of personal data it processed, a breach of GDPR Article 32(1). The regulator judged the company negligent.

The decision rests on two concrete findings, both summarized in IMY's press release:

  • No adequate control over software installations. According to SVT's reporting on the decision, an outdated firewall component from an external supplier was installed about a week before the breach, and its vulnerabilities were publicly documented. IMY held that verifying the component was Miljödata's job.
  • No automated real time monitoring. Nothing was watching the systems closely enough to flag the intrusion or suspicious activity as it happened.

"GDPR requires appropriate security measures for personal data. Miljödata failed here, resulting in an attacker accessing information about a large portion of Sweden's population," said Eric Leijonram, IMY's Director General, in the announcement (translated from Swedish).

What Happened in the August 2025 Attack?

Attackers breached Miljödata on August 25, 2025, stole a large volume of personal data, demanded 1.5 Bitcoin (about $168,000 at the time), and later published the stolen files under the name "Datacarry," as BleepingComputer reported.

The blast radius came from Miljödata's position in the market. Its systems are used by about 80% of Sweden's municipalities, and the attack reached more than 200 Swedish regional and municipal bodies. IMY lists a majority of municipalities, several regions, government agencies, and a large number of private companies among the affected customers.

The leaked records were not low stakes marketing data:

  • Swedish personal identity numbers (personnummer)
  • Contact information for employees and other data subjects
  • Sickness absence and rehabilitation information
  • Reports of school incidents, some involving minors

Miljödata told SVT it "deeply regrets" the impact and has remedied several of the deficiencies IMY identified. Neither IMY nor the company said publicly whether the decision will be appealed.

Empty Swedish municipal office at dusk with a network firewall appliance in the foreground, illustrating the Miljödata breach that exposed 2.2 million people

Is SEK 1.8 Million a Meaningful Penalty?

Measured per victim, no. SEK 1.8 million spread across 2.2 million people works out to about 82 öre each, or roughly 8 US cents using BleepingComputer's $183,000 conversion.

Put it next to the ransom and the number looks stranger. The attackers asked for about $168,000 in Bitcoin; the regulator asked for about $183,000. The criminal demand and the legal penalty for the same incident land within 10% of each other. Earlier this month we covered the CNIL's €500,000 fine against a French hospital after a breach touching 727,000 people, around 69 euro cents per person. Swedish public sector data, including children's school records, was priced at a fraction of that.

The headline figure is the wrong thing to focus on, though. Three elements of this decision matter more for compliance teams:

  • The processor was fined directly. Miljödata ran systems on behalf of municipalities, yet Article 32 applies to processors as well as controllers (see the GDPR text on EUR-Lex). Vendors cannot assume liability stops at the customer.
  • Customers are next. The open investigations into two municipalities and one region mean controllers who chose and supervised the vendor are being examined separately.
  • "Known vulnerability" is a finding, not an excuse. Installing a component whose flaws were already published on the supplier's website turned a supply chain problem into negligence.

Why Email Users Should Care

Leaked contact details paired with personnummer and sick leave history are raw material for convincing phishing. An email that cites your real employer, your actual absence dates, or your child's school sounds like HR, the Försäkringskassan, or a municipal office, because the sender has the same data those offices hold. Public sector breaches in the Nordics and Baltics keep following this pattern, as we saw when Latvian officials resigned over a 1.2 million record registry breach.

For anyone whose employer or school used Miljödata, the practical defaults are simple:

  • Treat any unexpected email or text that references sick leave, rehabilitation, or a school incident as suspect until you verify it through a phone number or portal you already know.
  • Never send your personnummer in reply to an email, however official it looks.
  • Ask your employer or municipality whether your records were in scope; GDPR gives you the right to ask a controller what it holds about you.

Email itself is frequently where the damage from a breach first shows up. A Canadian regulator found that email caused 64% of one province's privacy breaches, a reminder that the inbox is both the leak path and the follow up attack surface.

What Should Compliance Teams Do Now?

Compliance teams should read this decision as an audit checklist for their own vendors, because IMY's two findings map directly to questions you can ask any processor tomorrow. The NIST Cybersecurity Framework covers both under its Protect and Detect functions.

  • Ask for the change control process. Who approves third party components before they go into production, and do they check published vulnerability advisories first?
  • Ask for detection evidence. Is there automated, real time monitoring of the systems holding your data, and who responds to alerts outside office hours?
  • Map concentration risk. If one vendor serves 80% of your sector, a single intrusion becomes a national incident. Know which of your suppliers sit in that position.
  • Revisit your data processing agreements. Make Article 32 obligations, audit rights, and breach notification timelines explicit.

Larger penalties exist, such as the €825 million Uber fine from the Dutch DPA. The Miljödata case is useful for a different reason: it shows a regulator tracing a national scale breach back to one unchecked install and one missing alert.

What to Watch Next

The unresolved piece is the customer side. IMY has not named the two municipalities and one region under investigation, and it has not said when those cases will close. If any of them are fined, Swedish public bodies will have a precedent that choosing a vendor does not transfer accountability for the data it holds.

For the 2.2 million people in the Datacarry leak, the fine changes nothing about the data already circulating. Their identity numbers do not expire, and the phishing that uses them will not stop when the case file closes.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.