Back to Feed
PolicySep 29, 2026

IMY (Sweden) - IMY-2025-21177

Sweden's IMY fines IT company SEK 1.8M for GDPR violation after data breach.

Summary

Sweden's Data Protection Authority (IMY) has fined an IT company SEK 1,800,000 (€160,000) for failing to implement adequate security measures, leading to a data breach. The breach, caused by a ransomware attack exploiting a firewall vulnerability, exposed the personal data of approximately 2.2 million individuals, including sensitive health information and personal identification numbers. The DPA found that the company violated Article 32(1) of the GDPR due to insufficient technical and organizational measures.

Full text

Help IMY (Sweden) - IMY-2025-21177: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 06:45, 29 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators193 edits Tag: Decisions [1.0] (No difference) Latest revision as of 06:45, 29 September 2026 IMY - IMY-2025-21177 Authority: IMY (Sweden) Jurisdiction: Sweden Relevant Law: Article 32(1) GDPR Type: Investigation Outcome: Violation Found Started: Decided: 22.09.2026 Published: 23.09.2026 Fine: 1800000.0 SEK Parties: Miljödata i Karlskrona Aktiebolag National Case Number/Name: IMY-2025-21177 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Swedish Original Source: IMY (in SV) Initial Contributor: av The DPA fined an IT company SEK 1,800,000 (€160,000) for a failure to implement appropriate technical and organisational measures following a data breach affecting over 2 million individuals. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained unauthorised access to the personal data of approximately 2,200,000 individuals (the data subjects) by a ransomware attack, extracted this data from the systems, and published it on the dark web. Miljödata isolated all its servers and activated an external incident response team on the evening it detected the breach. Miljödata reported the personal data breach to the DPA six days after it had happened. The attacker had gained access to the compromised data by performing a so-called SQL injection against a support component of a firewall solution that Miljödata had installed on a server in its technical environment. A limited number of children were among the data subjects affected. The data leaked included personal identification numbers, names, phone numbers, home addresses, email addresses, employment data, and sick leave information. The DPA investigated whether Miljödata had implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk as required by Article 32(1) GDPR. Holding The DPA held that Miljödata had violated Article 32(1) GDPR by failing to implement appropriate technical and organisational measures and issued the company a fine of SEK 1,800,000 (€160,000). First, the DPA found that Miljödata had primarily acted as a processor and to a limited extent as a controller regarding the leaked data in its systems. As the obligation to implement appropriate technical and organisational measures in Article 32(1) GDPR applies to both controllers and processors, the DPA did not assess Miljödata's role concerning each processing activity in detail. Second, the DPA held that Miljödata had violated Article 32(1) GDPR. It considered the processing operations to pose high risks to the rights and freedoms of the data subjects. The processing was extensive – Miljödata had over 300 customers throughout Sweden, among them municipalities, regions, and other public entities. Moreover, the digital services Miljödata offered its customers involved extensive processing of sensitive personal data related to health, such as information on sick leave, data in rehabilitation documents, and information in medical certificates. The attacker had been present in Miljödata's technical environment for three days and gained access to additional information before the company's monitoring system had finally triggered an alert. The DPA concluded that the technical and organisational measures implemented by Miljödata had not met the high level of security required for the processing at issue. The support component that enabled the breach contained a critical vulnerability, was new, and had not undergone testing before being integrated in Miljödata's firewall system. When issuing the fine, the DPA held that Miljödata had acted negligently and considered the violation of Article 32(1) GDPR to have been of a serious nature. It took into account that the processing had been extensive and that the GDPR violation concerned Miljödata’s core business, where the company could be presumed to be well-positioned to implement appropriate security measures. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details. 1(17) Environmental Data in Karlskrona Aktiebolag Case Number: Decision Following an Inspection Pursuant to IMY-2025-21177 Date: General Data Protection Regulation – Miljödata i September 22, 2026 Karlskrona Aktiebolag Decision of the Swedish Data Protection Authority The Swedish Data Protection Authority finds that Miljödata i Karlskrona Aktiebolag (556324-4036) has processed personal data in violation of Article 32(1) of 1 the General Data Protection Regulation. The Swedish Data Protection Authority decides, pursuant to Articles 58(2) and 83 of the General Data Protection Regulation, that Miljödata i Karlskrona Aktiebolag shall pay an administrative fine of 1,800,000 kronor for the violation of Article 32(1) of the General Data Protection Regulation. Mailing Address: P.O. Box 8114 104 20 Stockholm Website: www.imy.se Email: imy@imy.se 1 Phone: Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with respect to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). the free movement of such data and repealing 08-657 61 00 Swedish Data Protection Authority Reference number: IMY-2025-21177 2(17) Date: September 22, 2026 Summary Miljödata i Karlskrona Aktiebolag (Miljödata) is a provider of digital system support for human resources and occupational health and safety management. Miljödata provides web-based services to customers for managing, among other things, sick leave, rehabilitation, and near-miss incidents. In August 2025, the company was subjected to a data breach by an external attacker who accessed information for which they lacked authorization within the services (unauthorized access). The breach was detected by Miljödata, which reported the personal data breach to IMY on August 26, 2025. Following the incident, Miljödata identified indications that the threat actor had extracted data from the systems, and the leaked information, which contained personal data, was published shortly thereafter on the Darknet. IMY has reviewed whether Miljödata, prior to and at the time of the personal data breach, had implemented appropriate technical and organizational measures in accordance with Article 32(1) of the General Data Protection Regulation to protect the personal data processed in its services. The review shows that the processing of personal data required a high level of security and that Miljödata has not taken sufficient measures to ensure that the personal data processed in the company’s services was protected against the risk of unauthorized disclosure or unauthorized access as a result of a data breach. Nor has the company implemented sufficient security measures, as it lacks automatic real-time monitoring to identify threats such as suspicious activity, intrusions, or attempted intrusions that could lead to unauthorized access. IMY assesses that Miljödata has acted negligently with regard to the violation of the General Data Protection Regulation that has been established and that all other conditions for imposing an administrative fine on Miljödata have been met. IMY decides that Miljödata shall pay an administrative penalty of 1,800,000 kronor for the violation of Article 3

Indicators of Compromise

  • malware — ransomware

Entities

IMY (vendor)firewall solution (product)external attacker (threat_actor)support component (product)