Sweden's privacy regulator IMY imposed a SEK 1.8 million (about US$183,000) administrative fine on IT provider Miljödata for inadequate technical and organisational security under Article 32(1) GDPR, following the 25 August 2025 attack that disrupted IT services in more than 200 Swedish regions and municipalities. Miljödata supplies work-environment and HR management systems used by 80% of Sweden's municipal systems, and the leaked data included personal identity numbers, contact information, sickness absence, rehabilitation records and school incidents involving minors; the attacker demanded 1.5 Bitcoin (about US$168,000 at the time) and published the data under the name "Datacarry". IMY's specific findings are the transferable lesson for suppliers of government-facing software: the company did not perform sufficient checks when installing new software and lacked automated real-time monitoring to detect intrusions and suspicious activity, a gap that let an intrusion proceed to exfiltration unnoticed. IMY has also opened investigations into two municipalities and one region in connection with the same attack, so further penalties may follow.
| Attribute | Detail |
|---|---|
| Sector | Legal Services |
| Date | 2026-09-24 |
| Source | BleepingComputer |
| Reliability | Tier 2 |