Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's IMY fined IT provider Miljödata $183,000 under GDPR for security failures behind an August 2025 breach affecting 2.2 million people.
Sweden's data protection authority IMY imposed a SEK 1.8 million ($183,000) fine on IT systems provider Miljödata for inadequate security leading to an August 2025 breach affecting 2.2 million people. The attacker demanded 1.5 Bitcoin (about $168,000) and leaked stolen data on the dark web as 'Datacarry', including personal identity numbers, sickness absence records, rehabilitation data, and school incidents involving minors. IMY found violations of GDPR Article 32(1), citing insufficient checks of newly installed software and no automated real-time intrusion monitoring. Investigations into two municipalities and one region are ongoing, with possible additional penalties.
- $183,000 (SEK 1.8M) GDPR fine for Article 32(1) security failures
- Breach affected 2.2 million people; data leaked under name 'Datacarry'
- Miljödata supplies work environment and HR systems to 80% of Swedish municipalities
- Further penalties possible as municipality investigations continue
Full article374 words · extracted from bleepingcomputer.com · click to collapse

Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
Miljödata is a Swedish software company that develops and provides work environment and HR management systems used by 80% of Sweden’s municipal systems.
Last year, on August 25, the company suffered a cyberattack that disrupted IT services in over 200 regions and compromised residents' sensitive data.
The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time) to prevent leaking the stolen information, but published it on the dark web under the name “Datacarry.”
The information included personal identity numbers, contact information, sickness absence, rehabilitation, and even school incidents involving underage individuals.
IMY launched an investigation in November 2025 to determine whether any security shortcomings violated the company’s obligations under the European Union’s General Data Protection Regulation (GDPR).
The agency has now confirmed that the company failed to adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity.
“IMY’s investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed,” reads the announcement.
“The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity.”
The negligence constitutes a violation of Article 32(1) of the GDPR, for which the agency imposed a penalty of $183,000.
Threat actors sometimes use the prospect of regulatory penalties to pressure victims into paying, and may set demands below what they believe an incident would ultimately cost, to incentivize victims to pay the ransom.
IMY noted that it has also launched investigations into two municipalities and one region in connection with the attack on Miljödata, which are ongoing, so additional penalties may be imposed in the future.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.