10/01/2026 | Press release | Distributed by Public on 10/01/2026 05:17
In August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a threat actor gained access to a large volume of personal data and subsequently published data on the Darknet. According to the company, the incident affected 2.2 million individuals. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.
IMY's review shows that the company did not maintain a sufficiently high level of technical and organizational security, given the types of personal data it processed. Miljödata failed to conduct adequate checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions or suspicious activity.
- The GDPR requires appropriate security measures for the personal data being processed. In this case, Miljödata has fallen short, resulting in a threat actor gaining access to data concerning a significant portion of Sweden's population. We take this incident very seriously. My hope is that other organizations also take note of this decision and, where necessary, review the security of the personal data they are responsible for, says Eric Leijonram, Director-General of IMY.
IMY assesses that Miljödata acted negligently and has therefore decided to impose an administrative fine of SEK 1.8 million for violating Article 32.1 of the General Data Protection Regulation (GDPR).
Among Miljödata's customers affected by the attack are a majority of Sweden's municipalities, several regions, and government agencies, as well as a large number of private companies. IMY has also initiated reviews of two municipalities and one region in connection with the attack on Miljödata. These reviews are ongoing.
Press Office, telephone +46 (0) 8 515 154 15