Sweden's independent data protection authority, IMY, has levied a penalty of $183,000 (SEK 1.8 million) against Miljödata, an IT infrastructure provider, for security deficiencies that allowed a breach in August 2025 to compromise personal information belonging to 2.2 million individuals.

Miljödata develops and operates work environment and human resources management platforms deployed across 80% of Sweden's municipal infrastructure. On August 25, the company fell victim to a cyberattack that disrupted services in more than 200 regional jurisdictions and exposed residents' confidential records.

The attackers, operating under the moniker "Datacarry," demanded 1.5 Bitcoin—approximately $168,000 at that time—as ransom to prevent disclosure of the stolen data. Despite the demand, the threat actors published the information on the dark web.

The compromised dataset contained personal identification numbers, contact details, sick leave records, rehabilitation information, and documentation of school-related incidents involving minors.

Security gaps identified

IMY initiated its investigation in November 2025 to assess whether Miljödata's operational practices breached obligations under the European Union's General Data Protection Regulation (GDPR). The regulator determined that the company maintained insufficient technical and organizational safeguards relative to the sensitivity of the personal information it handled.

The agency's findings revealed two critical deficiencies: the organization failed to execute adequate validation procedures when deploying new software applications, and it did not implement automated, continuous monitoring systems capable of identifying unauthorized access attempts and anomalous system behavior.

IMY's investigation shows that the company did not maintain a sufficiently high level of technical and organizational security, considering the types of personal data it processed. The company did not perform sufficient checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions and suspicious activity.

IMY announcement

These shortcomings constitute a violation of Article 32(1) of the GDPR, the provision governing technical and organizational measures for data security. The $183,000 penalty reflects this determination.

Additional investigations ongoing

IMY has opened separate investigations into two municipalities and one regional authority in connection with the Miljödata incident. Those inquiries remain active, and the regulator has indicated that further enforcement actions may follow.

Security researchers have noted that ransomware operators sometimes leverage the prospect of regulatory fines as a psychological tactic to coerce victims into payment, frequently setting ransom demands below the anticipated cost of a breach and resulting penalties to make compliance appear economically rational.