Key Takeaways
- IMY fined Miljödata SEK 1.8 million on 22 September 2026 for breaching GDPR Article 32.1, citing insufficient checks when installing new software and no automated real-time monitoring.
- The attacker entered on 20 August 2025 through an outdated firewall support component with a known critical vulnerability and went unnoticed for three days.
- Miljödata told IMY the incident covered about 2.2 million people. Prosecutors put the data published on the dark web at just over 1.5 million.
- Since 15 January 2026 Cybersäkerhetslagen covers every Swedish municipality and region and makes supply-chain security a mandatory measure.
- From 1 October 2026 MCFFS 2026:11 requires entities to assess suppliers before contracting and to supplement older contracts with security requirements where possible.
The Breach Happened at the Supplier but the Duty Now Sits with the Customer
On 23 August 2025 alarms about failing services at Miljödata in Karlskrona led to a discovery. Attackers had been inside its systems for three days. The company runs HR and work-environment software for a majority of Sweden’s municipalities, several regions and government agencies. On 22 September 2026 IMY fined it SEK 1.8 million. If you lead IT or security at a council or anywhere that shares a SaaS vendor with hundreds of others, the sharpest of the Miljödata breach lessons is not about Miljödata. Managing that supplier is now your legal duty.
The reason is a shift in where Swedish law places supplier risk. In August 2025 the old NIS law did not cover public administration as a sector so for most councils supplier security was a GDPR question handled through processor agreements. That is still true and IMY’s open reviews of three Miljödata customers are GDPR cases. Since 15 January 2026, however, Cybersäkerhetslagen has covered every municipality and region and made supply-chain security mandatory. From 1 October 2026 MCFFS 2026:11 adds concrete requirements including a duty to revisit older contracts.
What is NIS2 Article 21(2)(d) and Which Dates Matter?
NIS2 Article 21(2)(d) is the supply-chain security measure in the EU NIS2 Directive. It requires essential and important entities to manage the security of their relationships with direct suppliers and service providers. Article 21(3) adds that they must weigh each supplier’s specific vulnerabilities, the quality of its products and practices and its secure development procedures.
In Sweden the measure appears in 2 kap. 3 § of Cybersäkerhetslagen (2025:1506) as säkerhet i leveranskedjan. MCF (formerly MSB) wrote the detailed rules in MCFFS 2026:11, and since 1 July 2026 NCSC at FRA has taken over responsibility for them. The timeline below sets the incident against the regulatory dates.
The Dates That Matter
| 20 Aug 2025 | Attacker gains access through a firewall support component |
| 23 Aug 2025 | Alarms fire and Miljödata isolates its servers |
| 25 Aug 2025 | Customers informed and the 1.5 Bitcoin demand disclosed |
| Mid-Sep 2025 | Stolen data published on the dark web |
| 3 Nov 2025 | IMY opens reviews of Miljödata and three customers |
| 15 Jan 2026 | Cybersäkerhetslagen enters into force |
| Apr 2026 | Prosecutors close the criminal investigation |
| 22 Sep 2026 | IMY fines Miljödata SEK 1.8 million |
| 1 Oct 2026 | MCFFS 2026:11 security measure rules apply |
Miljödata Ransomware Attack and What IMY Found
Miljödata supplies web-based services for sick leave, rehabilitation and workplace incident reporting to more than 300 customers, many of them public bodies. The account below follows IMY’s decision and the prosecutor’s statements and goes no further.
How the Attacker Got In
According to Miljödata’s account in the decision, the attack began on 20 August 2025 with an SQL injection against a support component of a firewall solution. The component had been installed on an internet-facing server about a week earlier. Its vendor had delivered an outdated version with a known critical vulnerability, published on the vendor’s own website more than a year before.
Miljödata told IMY it saw no reason to check the version because the product was costly and came from a well-known vendor. IMY called that check a basic security measure.
Three Days Without a Security Alarm
The attacker escalated privileges and moved between servers despite two-factor authentication and separate admin accounts. Monitoring focused mainly on performance and availability so nothing flagged the intrusion until encryption broke the service on 23 August.
Miljödata isolated its servers about an hour after detection and has since added EDR and round-the-clock SOC monitoring.
What Leaked and Who It Reached
Miljödata told IMY the incident covered about 2.2 million people. The prosecutor’s figure for data leaked on the dark web is just over 1.5 million. The records included personal identity numbers, contact details and sensitive data on sick leave, rehabilitation and school incidents, some involving children.
Miljödata disclosed on 25 August that the attackers had demanded 1.5 Bitcoin. The data was published in mid-September 2025 by a group calling itself Datacarry.
The Fine and the Customer Reviews Still Open
IMY found a breach of GDPR Article 32.1 and set the fee at SEK 1.8 million, weighing the high severity against the company’s size. Miljödata has said it does not share all of IMY’s conclusions and the decision can be appealed to the Administrative Court in Stockholm.
Prosecutors closed the criminal investigation in April 2026 for lack of evidence. IMY’s reviews of Gothenburg, Älmhult and Region Västmanland remain open. They examine whether those customers had appropriate security for the personal data they kept in Miljödata’s system.
Who Must Comply With NIS2 Supply-Chain Security in Sweden?
Cybersäkerhetslagen applies to every region, municipality and kommunalförbund regardless of size. A municipality or region larger than a medium-sized enterprise counts as an essential entity and the rest as important entities. Private operators in the NIS2 annex sectors come into scope from medium size upwards.
A SaaS supplier does not fall under the law simply because its customers do. The customer’s duty to manage that supplier applies either way and it reaches the supplier through the contract.
Who Carries What
- Councils and regions : In scope regardless of size and essential if larger than a medium-sized enterprise
- Private operators : In scope in the NIS2 annex sectors from medium size upwards
- Shared SaaS suppliers : Bound through contracts and by the law only if they meet its criteria themselves
- IMY : Supervises GDPR, including security of processing under Article 32
Why Shared SaaS Vendors Concentrate Risk
The Miljödata attack was a supply chain attack in its plainest form. One intrusion reached hundreds of organisations because they had chosen the same supplier for the same function. No single customer’s assessment of Miljödata captured that combined exposure.
Miljödata’s own threat analysis rated the likelihood of a cyberattack as relatively low, partly because of its limited public profile, and the consequences as large. A low profile is no protection when one supplier holds data for hundreds of organisations.
MCFFS 2026:11 addresses both halves of this. Its general advice says entities should handle the risks of aggregating information. It requires them to manage continuity in digital supply chains especially where no alternative exists, and to ask suppliers about their own sub-suppliers where needed. Miljödata’s breach began one tier down, with a vendor that shipped an outdated component.
What to Do Before, During and After a Supplier Breach
Before: keep a supplier register that shows which systems each supplier runs, what personal data it holds and who to contact during an incident. The general advice in MCFFS 2026:11 describes this kind of inventory, including a record of outsourced processing.
During: treat your data as affected until the supplier shows otherwise. If the incident is significant for you, Cybersäkerhetslagen requires an early warning to the national CSIRT within 24 hours of becoming aware of it, a notification within 72 hours and a final report within one month. Personal data breaches go to IMY within 72 hours under GDPR.
Limit the supplier’s access to your own environment and warn staff that leaked data may be reused in phishing that mentions sick leave or rehabilitation cases.
After: ask for the root cause in writing, check whether the same component or vendor sits elsewhere in your estate and decide whether the contract still meets your requirements.
Penalties Under Cybersäkerhetslagen and GDPR
Cybersäkerhetslagen sets the sanction fee between SEK 5,000 and SEK 10 million for a public entity. Private entities face higher ceilings tied to global turnover. Failures that happened before 15 January 2026 still fall under the old law, so the gaps behind the Miljödata breach cannot be sanctioned under the new one.
GDPR runs in parallel. In the Miljödata decision IMY applied the Article 83(4) ceiling of EUR 10 million or 2 percent of turnover and set the fee well below it.
Sanction Ceilings at a Glance
- Public entity under Cybersäkerhetslagen: SEK 10 million
- Private essential entity: 2 percent of global turnover or EUR 10 million, whichever is higher
- Private important entity: 1.4 percent of global turnover or EUR 7 million, whichever is higher
- GDPR Article 32 breach: EUR 10 million or 2 percent of turnover, whichever is higher
How to Keep Supplier Risk Under Control From 1 October 2026
Assess the risk before you buy or outsource. MCFFS 2026:11 requires you to evaluate whether a supplier can meet your security requirements for the whole contract term and to make sure it meets the regulation’s requirements wherever you rely on it.
Revisit the contracts you already have. The regulation asks you to supplement agreements signed before 1 October 2026 with security requirements where possible and to handle the risk where that cannot be done.
Write a supplier incident notification clause. The general advice lists terms such as when and how the supplier tells you about suspected and actual incidents, threats and vulnerabilities, how sub-supplier risks are shared, joint exercises and early termination for non-compliance.
Test what you run. The regulation requires security tests to confirm systems are on the latest approved version and that published vulnerabilities are handled. Connect to the national CSIRT’s automatic vulnerability notifications, ANTS, unless that is clearly unnecessary.
Ask Every Shared Supplier the Miljödata Questions
IMY’s decision gives every council a ready-made checklist. Does your supplier verify the version and known vulnerabilities of what it installs? Does it monitor for intrusions in real time rather than only for uptime? Would its contract tell you within hours if either failed? Put those three questions to each supplier on your register before the end of the year and record the answers.
How eBuilder Helps
eBuilder Security’s CISO-as-a-Service provides senior security leadership on a part-time basis. It covers work such as vendor risk assessments, supplier registers and security requirements in supplier contracts and suits organisations that need that capability without a full-time CISO.
Frequently Asked Questions
What data was exposed in the Miljödata breach?
The leaked records included personal identity numbers, contact details, employment data and sensitive information on sick leave, rehabilitation and school incidents some involving children. Miljödata told IMY the incident covered about 2.2 million people, while prosecutors put the data leaked on the dark web at just over 1.5 million.
Why did IMY fine Miljödata?
IMY found that Miljödata breached GDPR Article 32.1 by failing to keep security appropriate to the risk. It did not check that a newly installed firewall support component was the correct version, and it lacked automated real-time monitoring to detect intrusions. The fine, set on 22 September 2026, was SEK 1.8 million.
Does NIS2 apply to Swedish municipalities?
Yes. Sweden implemented NIS2 through Cybersäkerhetslagen (2025:1506), in force since 15 January 2026. It covers every municipality, region and kommunalförbund regardless of size. Municipalities and regions larger than a medium-sized enterprise are essential entities and the others are important entities with supply-chain security among their mandatory measures.
What does NIS2 Article 21(2)(d) require?
It requires in-scope entities to manage supply-chain security, including the security of their relationships with direct suppliers and service providers. Under Article 21(3) they must weigh each supplier’s vulnerabilities, product quality, security practices and secure development procedures. In Sweden the detailed rules sit in MCFFS 2026:11 from 1 October 2026.
What should you do if a supplier is hacked?
Assume your data is affected until the supplier shows otherwise. Limit its access to your systems, assess whether the incident is significant for you and report within 24 hours if so. Report personal data breaches to IMY within 72 hours, warn staff about phishing and demand the root cause in writing.
This post is also available in:


