Sweden’s data privacy regulator, IMY, has imposed a fine of $183,000 (SEK 1.8 million) on Miljödata, an IT systems provider. The fine stems from inadequate security measures that resulted in a data breach in August 2025, impacting 2.2 million individuals.
Miljödata, a Swedish software company providing work environment and HR management systems to 80% of Sweden’s municipal systems, suffered a cyberattack on August 25, 2025. This attack disrupted IT services in over 200 regions and compromised sensitive personal data. The stolen information, which included personal identity numbers, contact details, sickness absence, rehabilitation records, and school incidents involving minors, was later published on the dark web by the threat actor, who demanded a 1.5 Bitcoin ransom.
IMY's investigation, launched in November 2025, confirmed that Miljödata failed to meet its obligations under the European Union’s General Data Protection Regulation (GDPR). Specifically, the company did not adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity. These deficiencies were deemed a violation of Article 32(1) of the GDPR, which mandates appropriate technical and organizational security measures.
The regulator noted that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed. This case underscores the importance of robust cybersecurity practices for organizations handling sensitive information, particularly those serving public sector entities. IMY has also initiated investigations into two municipalities and one region connected to the Miljödata attack, indicating potential further penalties.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Sweden's data privacy regulator, IMY, fined IT provider Miljödata $183,000 for inadequate security measures that led to a data breach affecting 2.2 million people in August 2025. The company failed to check new software and lacked real-time monitoring, violating GDPR Article 32(1). This fine highlights regulatory enforcement against insufficient cybersecurity practices, especially for providers handling sensitive personal data.