The Swedish authority fines Miljödata 1.8 million kronor for insufficient security after a massive data breach
The Swedish authority sanctions a system provider for insufficient technical and organizational security measures, leading to a massive data breach affecting 2.2 million individuals. The decision highlights the lack of adequate controls during new software installation and the absence of real-time system monitoring, measures considered fundamental given the sensitivity of the data processed.
Facts and context
The Swedish Data Protection Authority (IMY) today published a sanction decision against Miljödata i Karlskrona AB, including the imposition of a fine of 1,800,000 Swedish kronor (approximately €164,000), for failures related to the security of personal data processing.
The case originated from an investigation initiated by the authority following a significant data breach suffered by the company in August 2025, during which a malicious actor exfiltrated and then published data on the Tor network.
Grounds for the decision
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority concluded that the company did not implement an appropriate level of technical and organizational security considering the risks presented by the processing. It noted that the compromised data included national identification numbers, contact details, and sensitive data related to sickness absence, rehabilitation, or school incidents, concerning 2.2 million individuals. The investigation specifically demonstrated that the company did not perform sufficient controls during the installation of new software and lacked an automated, real-time monitoring system to detect intrusions and suspicious activities.
Authority's decision
Consequently, the authority imposed a fine of 1,800,000 Swedish kronor (approximately €164,000) on Miljödata i Karlskrona AB.
Lessons learned
This decision reminds that:
- The level of technical and organizational security must be rigorously proportionate to the nature and volume of data processed; large-scale processing of sensitive data requires particularly robust protection measures.
- Automated and real-time monitoring of information systems is an essential measure to quickly detect and respond to intrusions, and cannot be neglected by a controller or processor.
- Implementing control and validation procedures before installing any new software is a critical component of system security, to prevent the introduction of vulnerabilities.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire