← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Sweden fines Miljödata $183,000 for GDPR violations after 2025 data breach

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Miljödata fined $183,000 by Sweden's IMY.
  • Breach in August 2025 affected 2.2 million people.
  • Company lacked software checks and real-time monitoring.
  • Violation of GDPR Article 32(1) cited.

Regulatory Fine Issued

Sweden’s data privacy regulator, IMY, has imposed a fine of $183,000 (SEK 1.8 million) on Miljödata, an IT systems provider. The fine stems from inadequate security measures that resulted in a data breach in August 2025, impacting 2.2 million individuals.

Details of the Breach

Miljödata, a Swedish software company providing work environment and HR management systems to 80% of Sweden’s municipal systems, suffered a cyberattack on August 25, 2025. This attack disrupted IT services in over 200 regions and compromised sensitive personal data. The stolen information, which included personal identity numbers, contact details, sickness absence, rehabilitation records, and school incidents involving minors, was later published on the dark web by the threat actor, who demanded a 1.5 Bitcoin ransom.

Security Lapses Identified

IMY's investigation, launched in November 2025, confirmed that Miljödata failed to meet its obligations under the European Union’s General Data Protection Regulation (GDPR). Specifically, the company did not adequately check newly installed software and lacked automated, real-time monitoring mechanisms to detect intrusions and suspicious activity. These deficiencies were deemed a violation of Article 32(1) of the GDPR, which mandates appropriate technical and organizational security measures.

Broader Implications

The regulator noted that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed. This case underscores the importance of robust cybersecurity practices for organizations handling sensitive information, particularly those serving public sector entities. IMY has also initiated investigations into two municipalities and one region connected to the Miljödata attack, indicating potential further penalties.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Sweden's data privacy regulator, IMY, fined IT provider Miljödata $183,000 for inadequate security measures that led to a data breach affecting 2.2 million people in August 2025. The company failed to check new software and lacked real-time monitoring, violating GDPR Article 32(1). This fine highlights regulatory enforcement against insufficient cybersecurity practices, especially for providers handling sensitive personal data.