Sweden’s data protection authority, IMY, has fined IT systems provider Miljödata $183,000 (SEK 1.8 million) for failing to secure the personal data of 2.2 million people ahead of a ransomware attack in August 2025.
Miljödata builds work environment and HR management software used by roughly 80 percent of Sweden’s municipalities. On August 25, 2025, a cyberattack disrupted IT services across more than 200 regions and compromised residents’ sensitive information. The attackers demanded 1.5 Bitcoin, worth about $168,000 at the time, to prevent leaking the stolen data, then published it on the dark web under the name “Datacarry” when the ransom was not paid.
The leaked data reportedly included personal identity numbers, contact details, sickness absence and rehabilitation records, and information related to school incidents involving minors.
Investigation findings
IMY opened an investigation in November 2025 to determine whether Miljödata’s security practices violated the company’s obligations under the GDPR. The agency concluded that Miljödata did not maintain a level of technical and organizational security appropriate to the sensitivity of the data it processed.
Specifically, IMY found that the company failed to perform adequate checks when installing new software and had no automated, real-time monitoring in place to detect intrusions or suspicious activity. This negligence was found to violate Article 32(1) of the GDPR, which requires organizations to implement security measures proportionate to the risk of the data they handle.
The regulator noted that threat actors sometimes calibrate ransom demands below the anticipated cost of a regulatory fine, using the threat of penalties to pressure victims into paying rather than facing potential enforcement action.
More penalties possible
IMY said it has also opened investigations into two municipalities and one region connected to the Miljödata breach. Those inquiries are still ongoing, meaning additional fines tied to the incident could follow.
The case underscores the compounding regulatory exposure that can follow a ransomware incident involving sensitive personal data, particularly for vendors serving critical public sector infrastructure such as municipal HR and welfare systems.
