Swedish software provider fined after data breach exposed data of 2.2M people
Miljödata gets a €160,000 reminder that security checks matter.

Image by Cybernews.
- Sweden fined Miljödata about €160,000 for failing to protect sensitive personal data.
- Attackers exposed data from over 2.2 million people, including Social Security numbers and health-related details.
- Regulators said Miljödata lacked proper software checks and real-time monitoring to detect suspicious activity.
- IMY is still investigating two municipalities and one region linked to the same cyberattack.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
IMY, the Swedish privacy and data protection authority, has imposed a €160,000 fine on software provider Miljödata for failing to properly secure personal data that it handled.
In August 2025, Miljödata, a company that supplies software to municipalities and government agencies, was targeted by a cyberattack from an unknown threat actor.
The attackers came across a large amount of personal data, including Social Security numbers, contact details, and sensitive information about sick leave, rehabilitation, and school events.
The data was exfiltrated and subsequently published on the dark web. According to the company, over 2.2 million people were affected by the incident, including a majority of Swedish municipalities, several regions and government agencies, and a large number of private companies.
IMY launched an investigation to determine what technical and organizational measures Miljödata had implemented at the time of the incident. Given the personal and sensitive nature of the data being processed, those measures were insufficient.
According to the privacy regulator, the software supplier failed to carry out proper checks during the installation of new software. In addition, there was no automated real-time monitoring in place that was capable of detecting breaches and suspicious activities within its systems.
“GDPR requires appropriate security measures for the personal data it handles. Environmental data has broken down here, and the result is that a threat actor came across information about a large part of Sweden’s population,” Eric Leijonram, Director General at IMY, said in a statement.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“We take this incident very seriously. My hope is that other organizations will take this sanction to heart and, if necessary, review the security of the personal data for which they are responsible,” he concluded.
For infringing Article 32.1 of the GDPR, which states that both the data controller and data processor have to implement appropriate technical and organizational measures “to ensure a level of security appropriate to the risk,” Miljödata has to pay a penalty of approximately €160,000.
IMY is also currently investigating 2 municipalities and 1 region in connection with the same cyberattack. Those investigations are still ongoing.