Cyber & AI intelligence
Wasteland.
Briefs indexed2856
Issues29
Published Mondays07:30 CT
█ Ransomware MILJODATA-RANSOMWA 2026-09-24

Miljödata: Datacarry Ransomware Breach Draws SEK 1.8M GDPR Fine

"Sweden's data protection authority, Integritetsskyddsmyndigheten (IMY), has fined Miljödata i Karlskrona AB SEK 1.8 million (about $183,000). The fine covers the security failures behind the company's August 2025…"

Sweden's data protection authority, Integritetsskyddsmyndigheten (IMY), has fined Miljödata i Karlskrona AB SEK 1.8 million (about $183,000). The fine covers the security failures behind the company's August 2025 ransomware attack, in which a threat actor stole and then published personal data on about 2.2 million people. That is roughly one in five Swedes. IMY announced the decision on 22 September 2026 in its own press release. It found that Miljödata had acted negligently and breached Article 32(1) of the GDPR by failing to keep a sufficiently high level of technical and organisational security. The 2.2 million figure is the company's own count, and IMY reports it as "according to the company." Every source repeats that same number, so it has not been independently verified. Miljödata says on its website that it does not share all of IMY's conclusions. It can appeal to an administrative court within three weeks, according to Upphandling24.

What Happened

Miljödata builds web-based HR and work-environment systems that Swedish employers use to manage sick leave, rehabilitation, work injuries and incident reporting. Sources describe its reach differently:

These descriptions are broadly consistent, but none gives an exact customer count from a primary source.

Accounts of when the attack happened differ:

One possible reading is that intrusion began around the 20th and the disruption became visible later. The sources do not reconcile the dates, so treat both as reported.

The attack disrupted IT services for municipalities and regions across Sweden. NCIJ Network and TokyoBlackHatNews say services were disrupted in "over 200 regions." Sweden has only 21 regions, so that figure probably refers to municipalities or customer organisations, not regions in the Swedish administrative sense.

According to teiss, NCIJ Network and TokyoBlackHatNews, the attacker demanded 1.5 bitcoin (about $168,000 at the time) not to leak the data. The data was then published on the dark web under the name "Datacarry." IMY confirms that the data ended up on the darknet but does not name the group.

IMY opened its investigation in November 2025. It has also opened separate reviews of two municipalities and one region, which were Miljödata customers and are data controllers in their own right. Those reviews are still open. vpnlab.io names them as the City of Gothenburg, Älmhult municipality and Region Västmanland. IMY's announcement, as excerpted, does not name them. Upphandling24 also mentions a police investigation into aggravated unauthorised computer access (grovt dataintrång), but its current status is not clear from the available reporting.

What Was Taken

IMY lists the following categories among the exposed data:

vpnlab.io adds employment data. teiss, NCIJ Network and TokyoBlackHatNews say the school incident data includes cases involving minors.

This is not a routine credential dump. Health-adjacent absence and rehabilitation files are special-category data under GDPR. Once they are tied to a personnummer, they give a strong basis for targeted fraud, extortion and social engineering against individuals, and against the public-sector employers whose staff are in the dataset. Because the material was published openly, it should be treated as permanently exposed.

Why It Matters

Supplier concentration is the real risk. One HR/IT supplier held sensitive data for a large share of Swedish local government. One compromised vendor meant exposure across hundreds of organisations. IMY is also reviewing individual customers as controllers, which shows that outsourcing processing does not outsource accountability.

The fine is small compared with the damage. SEK 1.8M is modest for 2.2 million affected people. It is close to the reported ransom demand of about $168,000. BleepingComputer, via TokyoBlackHatNews, and NCIJ Network note that extortion groups sometimes set demands below the regulatory and recovery costs they expect a victim to face. Defenders should not read this fine as the upper limit of their exposure. Controller-level penalties, remediation, notification and litigation costs come on top.

Regulators are naming specific controls. IMY did not just say "security was inadequate." It pointed to two concrete gaps: no proper checks when installing new software, and no automated real-time monitoring for intrusions and suspicious activity. Expect those two controls to show up in future audits and procurement requirements.

Director General Eric Leijonram's message was aimed at everyone else. He said he hopes other organisations "take the sanction decision to heart" and review the security of the personal data they are responsible for.

The Attack Technique

The initial access vector was not phishing or stolen credentials. IMY's findings, as reported by teiss and Upphandling24, say Miljödata installed a support component for a firewall solution about a week before the attack. The installed version was outdated and had a long-known, critical vulnerability.

vpnlab.io goes further. It reports that the firewall vendor's own download page delivered the outdated build, and that the vendor had publicly documented the flaw more than a year earlier. This detail comes only from vpnlab.io's English and German articles. Treat it as reported, not confirmed. Neither the firewall vendor nor the CVE is named in the available sources.

In its defence, Miljödata told IMY it had no reason to doubt the installed version because it was an expensive product from a well-known supplier. IMY rejected that argument. According to vpnlab.io, the company never checked that the version it installed matched the one it had ordered.

After gaining access, the attacker reportedly moved laterally for about three days without being detected (vpnlab.io). That matches IMY's finding that Miljödata had no automated real-time monitoring. The operation followed the double-extortion pattern: data theft, a ransom demand, and publication when the demand was not met.

What Organizations Should Do

  1. Check every build before you install it. Compare the version, hash and signature of each software package against the vendor's current release notes and advisories before deployment. This matters most for security appliances and their add-ons. A trusted brand or a high price is not a control, and a vendor's own download page can serve an outdated build.
  2. Run a vulnerability scan on the day you install. Treat newly installed components, especially perimeter and firewall-adjacent ones, as unpatched until scanned. Check them against known-exploited vulnerability catalogues within 24 hours.
  3. Deploy automated, real-time detection. Three undetected days of lateral movement is a monitoring failure. Make sure EDR/XDR and centralised logging cover perimeter devices and internal east-west traffic, with alerts triaged around the clock, whether in-house or through an MDR provider.
  4. Audit processors holding special-category data. If you are a controller using an HR, health or case-management SaaS supplier, demand evidence of patch verification and monitoring. Don't accept a questionnaire tick-box. IMY's parallel reviews of Miljödata's customers show that controllers will be examined too.
  5. Reduce data concentration and retention. Limit how long sick-leave, rehabilitation and minors' incident records stay in live systems. Segment them from general HR data so that one intrusion does not expose every category at once.
  6. Prepare for post-leak fraud. Where your staff or residents appear in the Miljödata dataset, warn them about targeted phishing and impersonation that uses personnummer and health-related detail. Harden identity verification on helpdesks.

Sources: Sweden fines Miljödata over a 2.2 million record leak | DN Direkt – Miljödata får böta 1,8 miljoner efter läckan | Swedish regulator fines IT provider Miljödata over data breach ... | Sweden fines Miljödata $183,000 over breach affecting 2.2 million -... | Miljödata: böter efter jätteläcka - Upphandling24 | Sanktionsavgift mot Miljödata för bristande säkerhet IMY | Bußgeld gegen Miljödata nach Leck über 2,2 Millionen | スウェーデン、220万人に影響した情報漏えいでMiljödataに18万3,000ドルの制裁金 – TokyoBlackHatNews