Sweden fines an IT supplier over a leak that hit one in five people in the country
Sweden's data protection authority IMY has fined Miljödata i Karlskrona AB 1.8 million kronor, about $183,000, over the security failures behind a ransomware attack in August 2025. The company's systems held records on 2.2 million people, roughly one in five residents of Sweden, and a large part of that was sick leave data, rehabilitation files and school incident reports.
The decision, dated 22 September 2026, is worth reading past the headline number. It sets out how the attacker got in, and it was not a stolen password or a phishing email. It was a firewall support component that the vendor's own download page delivered in an outdated build, carrying a critical flaw that the same vendor had documented publicly more than a year earlier.
In brief
- IMY fined Miljödata 1.8 million kronor for breaching Article 32(1) of the GDPR: insufficient technical and organisational security.
- The attacker got in through an outdated version of a firewall support component installed about a week earlier, then moved around the network for three days before any alarm went off.
- Data on 2.2 million people leaked: identity numbers, contact details, employment data, sick leave, rehabilitation documents and school incident files.
- Three customers, the City of Gothenburg, Älmhult municipality and Region Västmanland, are still under separate investigation as the controllers of that data.
What the regulator decided
Miljödata sells web based systems that Swedish employers use to handle sick leave, rehabilitation, work injuries and incident reports. Over 300 organisations were customers, most of them municipalities, regions and other public bodies, plus state agencies and private companies. IMY found two concrete failures. The company never checked that the software version it installed was the one it had ordered, and its monitoring was not capable of noticing an intrusion in progress.
"The GDPR requires appropriate security measures for the personal data you handle. Miljödata fell short here, and the result was that a threat actor got hold of data on a large part of Sweden's population," said Eric Leijonram, director general of IMY. The regulator classed the breach as high severity and the company's conduct as negligent, which is the legal threshold for a fine rather than a reprimand.
Miljödata argued for a reprimand instead. Its position was that a criminal attack was not its doing, that it had gone beyond what the regulation requires, and that nobody had filed a concrete claim for damages, which in its reading showed that no real harm had occurred. IMY rejected that line, pointing to Court of Justice rulings that losing control over your own personal data is itself damage, whether or not anyone later misuses it.
It started with a download
About seven days before the attack, Miljödata installed a support component for a firewall solution on a server in its own environment. The product came from a well known vendor and it was expensive, which is exactly the reason the company gave IMY for not verifying it: there was no reason to suspect a problem. The vendor shipped an outdated version. Nothing on the order page said so, and nothing during the download said so either. The build that arrived contained a known critical vulnerability, and information about that vulnerability had been sitting on the vendor's own website since early 2024.
The server was exposed to the internet. The component went in without a run through a test environment. On 20 August 2025 the attacker used an SQL injection against the flawed component, reached the server, escalated to the highest rights in the system, and began moving between servers. Encryption of several servers started overnight into 23 August, and the data was pulled out after that.
IMY's conclusion is blunt and generalisable: checking that you received the version you ordered is a basic security measure, not an optional extra, and skipping it on an internet facing server holding health data is negligence. Neither IMY nor Miljödata named the vendor or the vulnerability anywhere in the public decision.
- The vendor publishes information about the vulnerability in that version of the component on its own website.
- Miljödata orders and installs the component on an internet facing server. The version delivered is outdated.
- The attacker exploits it through an SQL injection, reaches the server and grants itself the highest rights.
- Encryption of several servers begins, followed by extraction of the data.
- Technical alarms about service errors fire in the afternoon. Miljödata isolates all servers.
- The company reports the incident to IMY and files a report with the police.
- Its forensic work finds indications that data was extracted.
- Parts of the stolen data appear on the dark web.
- IMY issues the 1.8 million kronor fine.
Two-factor authentication was switched on
This is the part that should unsettle anyone who runs a system. Before the attack Miljödata had multi-factor authentication on internal services and separate accounts for separate roles. Attachments and free text fields were encrypted. None of it mattered, because the privileges the attacker took on that one server let it walk past antivirus detection, security monitoring and the multi-factor requirement alike.
Monitoring was the second failure. Miljödata did have monitoring systems, but they were built to watch performance and availability. For three days nobody saw an intruder moving laterally between servers. What eventually raised the alarm, on the afternoon of 23 August, was the service breaking. IMY noted that the company introduced round the clock SOC monitoring shortly after the incident, which it read as proof that this was within reach before it.
What share of Sweden's population ended up in this single leak?
About 21%. Records on 2.2 million people sat in these services, and Sweden had 10.6 million residents in mid-2026. One supplier with 58.5 million kronor in annual revenue was holding HR and health data on a fifth of a country.
Why the fine looks small
Article 83(4) of the GDPR caps fines for a security failure at 10 million euros or 2% of global annual turnover, whichever is higher. Miljödata's turnover for 2025 was 58,476,045 kronor, so the 2% figure came to 1,169,521 kronor. Because that is lower than the fixed ceiling, the maximum available to IMY in this case was 10 million euros, close to twice what the company earns in a year.
IMY stopped at 1.8 million kronor. It weighed high severity against the size of the company, and treated one thing as mitigating: in the days after the attack, before any investigation opened, Miljödata held individual meetings with several hundred affected employers and acted as a coordination point towards the association of Swedish municipalities and regions. Spread across the people in the leak, the fine works out at roughly 0.82 kronor each, about eight US cents.
The bill is also not final. Under the GDPR a supplier processing data on someone else's behalf and the employer who decided to put the data there are separately accountable, and the employers are still being examined.
| Party | Role under the GDPR | Outcome so far |
|---|---|---|
| Miljödata i Karlskrona AB | Processor for customer data, controller in a limited part | 1.8 million kronor for breaching Article 32(1) |
| Gothenburg, Älmhult, Region Västmanland | Controllers | Investigations open, no decision yet |
| The other 300 or so customers | Controllers | No investigations announced |
| Vendor of the firewall component | Not a party to the case | Not named publicly, no proceedings |
| The attacker | Outside the regulation | Data published on the dark web, police report filed |
Who else keeps this kind of data
Sweden is not unusual here. In most countries a short list of suppliers handles payroll, occupational health and HR case management for the bulk of the public sector, because every municipality buying its own system would be absurd. The trade-off is that a single bad install puts a fifth of a country's residents into a dark web archive, and none of those residents ever chose the supplier, saw its security review or knew it existed.
The same shape shows up elsewhere: last year a breach at a Polish medical system put national identity numbers together with health records in one archive, the combination that does the most damage precisely because it cannot be undone. Read that case for comparison: a medical system in Poland and 18.8 million cards. A leaked password gets changed in a minute. A Swedish personnummer, a Polish PESEL or any other lifelong identifier does not get reissued because a supplier lost it.
What to do if you could be in a leak like this
There is no clean recovery from this kind of incident, but a few things genuinely reduce the damage, and they apply well beyond Sweden.
- Treat the identity number as public. It will not be reissued, so any service that still treats it as a secret is the weak point, not you.
- Expect accurate phishing. Messages that quote your real employer, real absence dates or a real case number are the predictable next step, and they work because the details check out.
- Check what is already circulating. The Miljödata set on Have I Been Pwned covers 870,108 email addresses along with names, phone numbers, addresses, dates of birth and identity numbers.
- Ask your employer, not the supplier. The employer is the controller and owes you an answer about what was in the system, including records from jobs you left years ago.
- Use whatever fraud block your country offers. Credit freezes and fraud markers at credit bureaus exist in most places and cost nothing.
The scam that follows a leak is usually mundane rather than clever. A Latvian vehicle register breach turned into a wave of fake traffic fines within days, and the messages were convincing because the plate numbers were real: how the fake fines worked after the CSDD leak.
Am I affected if I have never lived in Sweden?
Can a leaked personal identity number be changed?
Would a VPN have helped here?
Why was the supplier fined and not the municipalities?
Which vendor shipped the outdated component?
• Sanktionsavgift mot Miljödata för bristande säkerhet - IMY
• Beslut efter tillsyn enligt dataskyddsförordningen, Miljödata i Karlskrona AB (PDF) - IMY
• Tillsyn: Miljödata i Karlskrona AB - IMY
• IMY inleder granskningar utifrån Miljödata-läckan - IMY
• Sweden fines Miljödata $183,000 over breach affecting 2.2 million - BleepingComputer
• Data breach at major Swedish software supplier impacts 1.5 million - BleepingComputer
• Miljonavgift för Miljödata efter stora läckan - SVT Nyheter
• Miljödata breach entry - Have I Been Pwned
• Fortsatt låg befolkningsökning under första halvåret 2026 - SCB