Compliance · · 4 min read

Swedish regulator fines Miljödata over breach affecting 2.2 million

Sweden’s data protection authority has fined software provider Miljödata after weaknesses in its security exposed sensitive records held for public-sector organisations.

Sweden’s data protection authority has fined software supplier Miljödata SEK 1.8 million, or about €160,000, after a cyberattack exposed personal information belonging to more than 2.2 million people. The decision was issued on September 22, 2026, and found that Miljödata breached Article 32(1) of the General Data Protection Regulation.

The ruling is significant because Miljödata’s systems are used widely across Swedish public services. The company provides human resources and workplace-safety software to municipalities, regions, government agencies and private employers. Its products operate in about 80% of Sweden’s municipal systems, giving an attack on the supplier consequences far beyond its own organisation.

Kobaran.com reports that the regulator identified shortcomings in both the company’s technical controls and its development procedures. Miljödata did not adequately test newly installed software before placing it into live use, while its systems lacked automated, continuous surveillance capable of detecting an intrusion as it occurred.

How the attack exposed sensitive records

The initial weakness was linked to third-party security software. According to the reporting on IMY’s decision, a vulnerable firewall component had not been properly assessed by Miljödata. The component remained in the company’s environment for around a week before attackers exploited it, despite information about its vulnerabilities already being available on the supplier’s website.

The resulting ransomware attack gave criminals access to a broad collection of records. The exposed material included Swedish personal identity numbers, contact information, sick-leave details, rehabilitation documentation and reports concerning incidents in schools. Some of those school records related to children.

The attackers sought 1.5 Bitcoin. After Miljödata declined to pay, the stolen information was posted on the dark web under the name Datacarry. The identity of the people or group responsible has not been established. A police inquiry into aggravated data intrusion and attempted aggravated extortion was later closed because investigators could not find enough evidence.

IMY’s finding was not that Miljödata should be punished merely because it suffered an attack. The authority instead concluded that the company had failed to apply security protections proportionate to the nature and sensitivity of the information in its care. It considered the failure negligent and held that the organisation had not maintained an adequate level of technical and organisational protection.

That distinction is central to data-protection enforcement. Organisations are expected to anticipate known weaknesses, assess the risks created by the data they process and maintain safeguards appropriate to those risks, rather than relying on the absence of previous attacks.

Why the fine reaches beyond Miljödata

The case also highlights the responsibilities of technology suppliers that process information on behalf of other organisations. GDPR enforcement commonly focuses on the public body or business that determines why and how personal data is used. In this instance, IMY pursued the processor directly because its own security failures contributed to the exposure.

The penalty is relatively small when measured against the number of people affected: roughly SEK 0.82 per person. Its wider importance lies in the principle that a supplier can face a direct regulatory sanction when inadequate controls at the supplier lead to a breach affecting its customers.

Article 32 applies to both data controllers and processors. It requires them to select security measures in line with the risks involved, considering factors including available technology and the character of the processing. Information about sick leave and rehabilitation falls within the GDPR’s specially protected health-related data, which increases the level of care expected.

The article’s lower penalty tier allows fines of up to €10 million or 2% of a company’s worldwide annual turnover, whichever is greater. IMY’s decision therefore sits well below the maximum available sanction, even though the breach involved a large number of people and highly sensitive material.

Public bodies remain under scrutiny

The regulator has not treated Miljödata’s fine as the end of the matter. IMY is investigating the city of Gothenburg, the Region of Västmanland and Älmhult municipality over their connection to the incident. Further penalties may be issued after those inquiries are completed.

Those investigations could examine how the public organisations selected Miljödata and how they supervised the supplier’s handling of employee and resident information. A processor’s obligations do not remove the duties of the public bodies that decide to entrust it with personal data.

Miljödata has indicated on its website that it disputes some of IMY’s conclusions. The company can challenge the decision in an administrative court within three weeks.

For the affected individuals, however, a successful appeal would not make the published records private again. The next regulatory decisions may therefore be more consequential for Swedish municipalities and regions, potentially influencing how they evaluate vendors, monitor outsourced systems and protect sensitive information in future contracts.

data protectioncybersecuritygdprswedenransomwarepublic sectorprivacydata breach

Continue reading

Read this in another language