The Swedish Data Protection Authority (IMY) has fined Miljödata 1.8 million Swedish kronor (S$1.1 million) for breaching its data protection laws in 2025, bringing one of the country's biggest data breaches back to the forefront . The company has been ordered to pay 1.8 million Swedish kronor (S$1.1 million ) after investigating the 2025 cyberattack.

The decision was published on 22 September 2026 and concerns Miljödata i Karlskrona AB, a provider of systems used by municipalities, regions and businesses in Sweden. IMY states that the company did not maintain an adequate level of technical and organizational security for the personal data it processed.
The case is not about a new attack. It is the administrative follow-up to the August 2025 incident, when Miljödata was attacked by a cyberattack and the stolen data was published on the dark web. The protection of personal data was at the center of the investigation. According to the company and reports, the leak affected approximately 2.2 million people.
See also: Miljödata: Data breach affects 1.5 million people
Personal data protection and the fine
In its reasoning, IMY points to two key weaknesses: Miljödata did not conduct sufficient checks when installing new software and did not have automated, real-time monitoring to detect intrusions and suspicious activity on its systems.
The Authority links the shortcomings to Article 32(1) of the General Data Protection Regulation (GDPR), which requires measures proportionate to the risks and nature of the data. The fine on Miljödata amounts to 1.8 million kronor, which corresponds to approximately $183,000.
The independent report by BleepingComputer says the data included ID numbers, contact information, sick leave information, and rehabilitation data. The exact extent of each category is attributed to available reports, not a new list published by IMY.

An attack with consequences beyond the company
The August 2025 attack caused disruptions to services used by more than 200 regions, while Miljödata had a significant presence in municipal systems in Sweden. The perpetrator who claimed responsibility reportedly demanded a ransom and later published information online under the name Datacarry.
The reports of 2.2 million people affected refer to the number reported by Miljödata. IMY, in its brief statement, confirms the large-scale leak of personal data and the decision on the fine, without repeating the full population assessment there.
The decision also has implications for organizations that outsource critical functions. Having setup procedures and ongoing monitoring are not just technical details; they are part of the responsibility for protecting data throughout the supply chain.
Personal data security therefore requires checks before any change, not just after signs of a breach appear. Security managers need to know which systems have access to sensitive information and who can approve a new installation.
Miljödata's experience also shows that privacy protection needs measurable traces: logs, notifications of unusual actions, and tests that prove that processes are working. Without these, early detection and documentation of compliance remain weak.

See also: Grindr: Fined £26 million for HIV data leak
What the decision means for organizations
The Miljödata fine shows that GDPR compliance is not limited to having policies or filing reports after an incident. Organizations need to control software changes, restrict access rights, log unusual activity, and test response plans.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
IMY has also initiated audits for two municipalities and one region linked to the case. The investigations are still ongoing, so additional decisions or sanctions are likely to follow. The outcome will show how responsibility is divided between the technology provider and the organizations that used its services.
For businesses, the key message is practical: new code deployments should be accompanied by audits, while critical infrastructures need continuous detection and a clear process for immediate isolation. The SecNews technical team also recommends regular recovery exercises and auditing contracts with external providers.

See also: Ransomware in Berlin: Rhysida threatens to leak government data
The Miljödata case is a reminder that a breach does not end when systems are restored. The evaluation of controls, public awareness, and accountability for security gaps continue for months or even years after the initial attack.
