
IMY, the Swedish Authority for Privacy Protection, has launched an investigation after a breach at IT company Miljödata exposed sensitive data on 1.5 million individuals.
In August 2025, Swedish system supplier Miljödata suffered a major ransomware attack. Personal information was taken from Adato, a rehabilitation support system, and Novi, a system used for HR personnel notes.
The incident affected around 25 private companies—including major firms like Scandinavian airline SAS and metals company Boliden—as well as approximately 200 Swedish municipalities, including the capital, Stockholm.
On September 13, the DataCarry ransomware group claimed responsibility for the cyberattack on Miljödata, listing the organisation on its data leak site. Following a failed ransom negotiation, the group published the stolen data on September 14. The leaked data was added to Have I Been Pwned, revealing 870,000 unique email addresses, along with names, addresses, phone numbers, government IDs, dates of birth, and gender.
In a recent press release, the Swedish Authority for Privacy Protection (IMY) announced it has launched an investigation into the cyberattack on Miljödata, which impacted several public and private organisations across Sweden.
“According to the Swedish Public Prosecutor’s Office, information on over 1.5 million private individuals was published. IMY has been in contact with Miljödata and several affected businesses since the attack. What is now being initiated are inspections based on the General Data Protection Regulation, GDPR,” IMY said.
IMY added that due to the number of affected parties, a selection has been made based on their activities and identified risks. The audits will cover Miljödata, the City of Gothenburg, Älmhult Municipality, and Region Västmanland. Additional audits may be conducted, but none are currently planned by the authority.
The audit of Miljödata focuses on security issues related to the data breach, while the audits of the region and two municipalities will examine their handling of personal data in Miljödata’s system—particularly concerning protected identities, former employees, and children.
In a statement shared with the media, Jenny Bård, IMY’s head said, “The Miljödata leak meant that a large part of Sweden’s population had their personal data published on the Darknet, in many cases also sensitive data. The leak raises a number of questions about what security has been like and what types of personal data have been in the systems.
“Central to us is to investigate any shortcomings that can provide lessons for the future, to reduce the risk of this type of incident happening again,” he added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543