Integritetsskyddsmyndigheten (IMY), Sweden’s data protection authority, has fined Miljödata i Karlskrona AB SEK 1.8 million for failing to protect the personal data it handled for a majority of the country’s municipalities. The decision, published on 22 September, closes IMY’s review of the August 2025 attack that the company says affected 2.2 million people.
IMY found two concrete failures. Miljödata did not carry out sufficient checks when installing new software and it had no automated real-time monitoring to detect intrusions or suspicious activity. The regulator judged the company negligent and ruled that it breached Article 32(1) of the GDPR which requires security appropriate to the data being processed.
The data was not trivial. According to IMY, it included personal identity numbers, contact details and sensitive information on sick leave, rehabilitation and incidents in schools.
A Fine Roughly the Size of the Ransom
BleepingComputer reports that the attackers demanded 1.5 Bitcoin, worth about $168,000 at the time, and published the stolen data on the dark web when the demand went unpaid. IMY’s fine converts to roughly $183,000.
That symmetry is the weakest part of the decision. A penalty barely larger than the extortion demand will not change anyone’s cost calculation, and extortion groups already point to regulatory exposure when pressing victims to pay. The number is not the signal. The finding is.
IMY Has Put Missing Monitoring on the Record
The decision names the absence of real-time intrusion monitoring as a failing in its own right, next to the software checks. For a supplier holding HR and sick-leave records for hundreds of public bodies, IMY’s position is that nobody watching the systems is itself a breach of the law.
IMY director general Eric Leijonram said Miljödata had fallen short and that as a result “a threat actor obtained data on a large part of Sweden’s population”. He asked other organisations to review the security of the personal data they are responsible for.
Two Municipalities and a Region Are Still Under Review
Miljödata’s customers include a majority of Sweden’s municipalities, several regions, state agencies and a large number of private companies according to IMY. The regulator has also opened reviews of two municipalities and one region connected to the attack. It has not named them.
The customer impact was visible within days of the attack. Miljödata chief executive Erik Hallén told TT in August 2025 that around 200 municipalities and regions were hit by outages and Helsingborgs stad shut down two systems holding rehabilitation and workplace injury data, SVT reported.
Buying the system did not hand over the responsibility. The municipality whose staff records sat in Miljödata still answers for how they were protected, and IMY is now testing exactly that.
Three Questions to Ask Your Suppliers Before the Next Contract Renewal
- Is the environment where your personal data is stored monitored in real time and who responds to an alert at three in the morning?
- What checks are carried out before new software reaches those systems?
- How quickly are you notified in the event of an incident and is that time limit specified in the contract?
Then ask the same three questions about your own environment. IMY has just shown which answers the authority considers negligent.
References
- Sanktionsavgift mot Miljödata för bristande säkerhet
- Sweden Fines Miljödata $183,000 Over Breach Affecting 2.2 Million
- Flera kommuner i Skåne drabbade av it-attack: ”Mycket olyckligt”
This post is also available in:

