Sweden IMY fines Miljödata SEK 1.8M after Aug 2025 breach hit ~2.2M people (municipal HR systems)
Swedish Authority for Privacy Protection (IMY) press release (22 September 2026) imposes an administrative fine of SEK 1.8 million (~US$183k) on system supplier Miljödata i Karlskrona AB for inadequate technical/organisational security (GDPR Art. 32.1) after an August 2025 intrusion. Per IMY/Miljödata: ~2.2 million people affected; stolen data included personal identity numbers, contact details and sensitive fields (sickness absence, rehabilitation, school incidents involving minors) later published on darknet; customers included a majority of Sweden’s municipalities plus regions, agencies and private firms. IMY finds insufficient checks when installing new software and no automated real-time monitoring for intrusions/suspicious activity; agency also opened related reviews of two municipalities and one region (ongoing). Wire: BleepingComputer 22 Sep 2026. Primary: IMY pressmeddelande.
- Product
- Miljödata work-environment / HR systems (Swedish municipal and enterprise customers)
- Exploited in Australia?
- unknown
- Patch to
- No AU product CVE: treat as GDPR security-control lesson for suppliers holding HR/health identity data — software-change controls, real-time intrusion monitoring, and supplier due diligence for council/agency SaaS
Primary: IMY — Sanktionsavgift mot Miljödata för bristande säkerhet (22 Sep 2026) · BleepingComputer — amplify (22 Sep 2026)
