Sweden’s IMY fined Miljödata $183,000 after finding that inadequate security measures contributed to a 2025 breach affecting 2.2 million people and exposing highly sensitive personal data. The attack, attributed to the “Datacarry” threat actor, disrupted services across more than 200 regions and is now linked to further investigations into affected municipalities and one region. #Miljödata #IMY #Datacarry #GDPR
Keypoints
- IMY fined Miljödata SEK 1.8 million for GDPR security failures.
- The August 2025 breach affected 2.2 million people in Sweden.
- Miljödata’s systems are used by 80% of Sweden’s municipal systems.
- The attacker, “Datacarry,” leaked stolen data on the dark web after demanding 1.5 Bitcoin.
- IMY found poor software checks and no real-time monitoring for intrusions.