Threats & Attacks

Nyköping Municipality Website Hacked, Showed Death Note Image for Half an Hour

MCFFS 2026:11 Took Effect the Day Before Municipalities have been in scope of Cybersäkerhetslagen since 15 January. On Thursday 1 October, the day before the defacement, MCFFS 2026:11 entered into force: the regulation on security measures decided by MCF (formerly MSB) on 15 June and administered by NCSC at FRA since 1 July. Three of its provisions apply directly to what happened on Friday evening. Chapter 4, section 19 requires an operator to identify and handle the need for other organisations and individuals to verify its identity in digital channels; the general advice lists web pages alongside email, SMS and phone calls. Section 17 of the same chapter requires multi-factor authentication for staff and supplier access to the digital environment over an external network. Section 20 requires the operator to identify and handle the need to monitor the digital environment and to raise alarms when security fails. Monitoring is where the municipality's own account shows a result: the change was spotted, isolated and reversed in roughly half an hour on a Friday evening. It has not said how the access route used was protected or whether multi-factor authentication was in place, so sections 17 and 19 cannot be assessed from outside. The question the IT department's analysis will have to answer is who was able to publish that image, and from where. References Störningar på nykoping.se Nyköpings kommun hackad: visade karaktär från animeserie Nyköpings kommuns hemsida hackad i cyberattack Region Sörmlands hemsida låg nere: inga tecken på intrång MCFFS 2026:11 Föreskrifter och allmänna råd om säkerhetsåtgärder och ledningens utbildning Nya krav ska stärka Sveriges cybersäkerhet

Visitors to nykoping.se at around 20.30 on Friday 2 October were met by L, a character from the Death Note anime, and the words “Imagine att bli hackad i 2026. Ni borde fixa detta”: imagine getting hacked in 2026, you should fix this. Södermanlands Nyheter was first to report it. According to SVT Sörmland, the image had been removed and the site appeared to work normally again by about 21.00. Nyköping municipality has published a short notice and has not said how the page was changed.

The Notice Published at 21.30

The municipality’s notice went up on its own site at 21.30 and is still its only public statement. It says nykoping.se was temporarily affected by a hacker attack during Friday evening and that the IT department discovered someone had manipulated the municipality’s web. According to the notice, the problem was identified, isolated and fixed. Nothing else is affected for now, it says, and the IT department will analyse what happened. Communications chief Åsa Helldén Ruocco referred SVT to that text on Friday night. Who was behind the defacement and why is unknown.

The notice calls the problem isolated, but the analysis that would confirm this has not been published. Nothing released so far says whether the page was changed through the content management system through the hosting provider or with a stolen login. Until that is known, the only public verdict on the site’s security is the attacker’s own message.

A municipality’s website is an official channel residents use for information and contact details and anything an outsider places there carries the municipality’s name for as long as it stays up. Posting an image also means someone had the ability to publish on the site. The same access could have been used for changes that are harder to spot such as altered contact details or links.

The next morning all of Region Sörmland’s websites went down for what the region says was a file problem on a server with no sign of an intrusion. The region sees no connection between the two events.

MCFFS 2026:11 Took Effect the Day Before

Municipalities have been in scope of Cybersäkerhetslagen since 15 January. On Thursday 1 October, the day before the defacement, MCFFS 2026:11 entered into force: the regulation on security measures decided by MCF (formerly MSB) on 15 June and administered by NCSC at FRA since 1 July. Three of its provisions apply directly to what happened on Friday evening.

Chapter 4, section 19 requires an operator to identify and handle the need for other organisations and individuals to verify its identity in digital channels; the general advice lists web pages alongside email, SMS and phone calls. Section 17 of the same chapter requires multi-factor authentication for staff and supplier access to the digital environment over an external network. Section 20 requires the operator to identify and handle the need to monitor the digital environment and to raise alarms when security fails.

Monitoring is where the municipality’s own account shows a result: the change was spotted, isolated and reversed in roughly half an hour on a Friday evening. It has not said how the access route used was protected or whether multi-factor authentication was in place, so sections 17 and 19 cannot be assessed from outside.

The question the IT department’s analysis will have to answer is who was able to publish that image, and from where.

References

  1. Störningar på nykoping.se
  2. Nyköpings kommun hackad: visade karaktär från animeserie
  3. Nyköpings kommuns hemsida hackad i cyberattack
  4. Region Sörmlands hemsida låg nere: inga tecken på intrång
  5. MCFFS 2026:11 Föreskrifter och allmänna råd om säkerhetsåtgärder och ledningens utbildning
  6. Nya krav ska stärka Sveriges cybersäkerhet

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.