Swedish software provider Miljödata has been fined SEK 1.8 million after regulators concluded that inadequate security contributed to a major data breach affecting approximately 2.2 million people.
The cyberattack took place in August 2025 and compromised systems used to process information for organizations across Sweden. Miljödata supplies workplace and HR-related software to a large number of municipalities, regional authorities, government agencies and private companies, giving the incident an unusually broad reach.
According to Sweden’s privacy regulator, the exposed information included personal identity numbers, contact details and sensitive records involving sick leave and workplace rehabilitation. Data concerning incidents involving pupils at schools was also affected. Information obtained during the attack was later published on the dark web.
The Swedish Authority for Privacy Protection found that Miljödata had not implemented technical and organizational safeguards appropriate for the sensitivity and scale of the information it handled.
One of the regulator’s central findings concerned software installed shortly before the attack. Miljödata said a firewall component supplied by another company had been installed roughly a week before the intrusion. However, the component was an outdated version containing known vulnerabilities.
Information about those security weaknesses was already publicly available from the supplier. Miljödata argued that it had relied on a costly product from a well-known vendor, but the regulator concluded that the company remained responsible for verifying that the technology provided adequate protection.
Investigators identified another weakness in Miljödata’s ability to detect an attack. The company lacked automated real-time monitoring capable of identifying intrusions and suspicious activity within its systems.
The regulator concluded that these failures amounted to negligent handling of personal information and violated Article 32(1) of the GDPR, which requires organizations to implement security measures appropriate to the risks surrounding the data they process.
Miljödata says it takes the decision seriously but does not agree with every conclusion reached by the regulator. The company says the shortcomings identified during the investigation have already been addressed and that external specialists have been brought in to strengthen its security.
