Swedish software provider Miljödata has been fined SEK 1.8 million, approximately $183,000, after regulators concluded that inadequate security contributed to a major data breach affecting around 2.2 million people.
Sweden’s privacy authority investigated the company following a cyberattack discovered in August 2025. Attackers gained access to Miljödata’s IT environment and obtained large amounts of personal information stored in systems used by municipalities, regional authorities, government agencies and private organizations across Sweden.
The compromised information included personal identity numbers and contact details alongside more sensitive records. Some affected systems contained information about sickness absence and rehabilitation, while others held details about incidents involving students at schools.
Stolen information was subsequently published on the dark web. The scale of the incident was particularly significant because Miljödata provides workplace and human resources software to a large portion of Sweden’s public sector.
The privacy investigation focused on whether Miljödata had taken appropriate technical and organizational measures to protect the information it processed. Regulators concluded that its protections did not match the sensitivity and volume of personal data held in its systems.
One problem involved software installed shortly before the intrusion. Miljödata told regulators that attackers entered through a firewall component supplied by another company. The product had been installed about a week before the attack, but the deployed version was outdated and contained known vulnerabilities.
Information about those vulnerabilities was publicly available from the supplier. Miljödata argued that it had no reason to question the product because it came from a well-known vendor and represented a significant investment, but regulators concluded that the company remained responsible for verifying that its systems provided adequate protection.
Investigators also found that Miljödata lacked automated real-time monitoring capable of identifying intrusions and suspicious activity. Combined with insufficient checks during software installation, the weaknesses were considered a violation of Article 32(1) of the GDPR, which requires organizations to implement security measures appropriate to the risks surrounding personal data.
The regulator described the security shortcomings as serious given the scale of the breach and the sensitive information involved. Miljödata has since said it deeply regrets the impact on customers and affected individuals and has addressed several weaknesses identified during the investigation.
The regulatory consequences may not end with Miljödata. Swedish authorities are separately investigating two municipalities and one region that used the company’s services to determine whether they also met their responsibilities for protecting personal information.