Sweden fines Miljödata after breach exposing data of 2.2 million people
The GDPR ruling highlights weak security at a key municipal IT supplier and opens the door to more probes of local authorities.
Sweden’s privacy regulator IMY has fined Swedish HR and work-environment software provider Miljödata SEK 1.8 million (about $183,000) for GDPR security failures tied to an August 2025 ransomware breach. The incident affected systems used by 80% of Sweden’s municipal organizations, disrupting IT services in over 200 regions and exposing sensitive data for about 2.2 million people, including health-related and school-incident records about minors. Attackers demanded 1.5 Bitcoin (then roughly $168,000) to avoid leaking the stolen data but later published it on the dark web under the alias “Datacarry.” IMY’s investigation found Miljödata lacked adequate checks on new software and did not have automated real-time monitoring to detect intrusions, concluding this violated GDPR Article 32(1). IMY is also investigating two municipalities and one region connected to the attack, so additional regulatory penalties may follow for other controllers relying on Miljödata’s systems.
Why it matters
IMY’s decision puts direct regulatory pressure on a core HR and work-environment software provider whose systems reach 80% of Sweden’s municipal organizations, after a ransomware attack disrupted services in over 200 regions and exposed sensitive data on millions of residents, including minors. The finding that Miljödata’s safeguards fell short of GDPR requirements, and the open investigations into municipalities and a region that relied on its systems, signal that both vendors and public-sector customers face closer scrutiny of how they protect personal data.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.