2025 Miljödata — Datacarry ransomware; 2.2M people; IMY SEK 1.8M GDPR fine (Sep 2026)
Data compromised
Per IMY / BleepingComputer: personal identity numbers, contact information, sickness absence, rehabilitation data, and school-incident records involving minors among compromised material. Ransom demand ~1.5 BTC refused; data published as Datacarry.
Technical writeup
Verified Swedish IMY enforcement — announced September 22, 2026 regarding August 25, 2025 attack on Miljödata (HR/work-environment SaaS used by ~80% of Swedish municipal systems). Attack disrupted 200+ regions; Datacarry published stolen data after unpaid ~1.5 BTC demand. IMY: insufficient checks on newly installed software and no automated real-time intrusion monitoring — GDPR Art. 32(1); SEK 1.8M (~$183k) fine. Separate municipality/region probes ongoing. Distinct from earlier miljodata-2024 catalog row. recordsAffected 2200000; companyConfirmed true.
Root cause
August 2025 cyberattack / Datacarry leak; IMY found inadequate software checks and missing real-time intrusion monitoring (Art. 32 GDPR)