Incident
Published 2026-09-22
Verified 2026-09-27

Sweden IMY fines Miljödata SEK 1.8M after Aug 2025 breach hit ~2.2M people (municipal HR systems)

Swedish Authority for Privacy Protection (IMY) press release (22 September 2026) imposes an administrative fine of SEK 1.8 million (~US$183k) on system supplier Miljödata i Karlskrona AB for inadequate technical/organisational security (GDPR Art. 32.1) after an August 2025 intrusion. Per IMY/Miljödata: ~2.2 million people affected; stolen data included personal identity numbers, contact details and sensitive fields (sickness absence, rehabilitation, school incidents involving minors) later published on darknet; customers included a majority of Sweden’s municipalities plus regions, agencies and private firms. IMY finds insufficient checks when installing new software and no automated real-time monitoring for intrusions/suspicious activity; agency also opened related reviews of two municipalities and one region (ongoing). Wire: BleepingComputer 22 Sep 2026. Primary: IMY pressmeddelande.

Product
Miljödata work-environment / HR systems (Swedish municipal and enterprise customers)
Exploited in Australia?
unknown
Patch to
No AU product CVE: treat as GDPR security-control lesson for suppliers holding HR/health identity data — software-change controls, real-time intrusion monitoring, and supplier due diligence for council/agency SaaS

Primary: IMY — Sanktionsavgift mot Miljödata för bristande säkerhet (22 Sep 2026) · BleepingComputer — amplify (22 Sep 2026)

breaches identity