← Tietoevry

2024 Tietoevry — Akira ransomware in Swedish hosting DC; Primula and public-sector customer outages

2024 Unknown records affected Share on X

Data compromised

Customer-operational datasets across tenant environments—population accounting dispersed across Swedish agencies and enterprises rather than one consumer numerator

Technical writeup

Finnish IT services giant Tietoevry confirmed a January 2024 encryption-and-extortion event confined to colocated infrastructure in Sweden, knocking payroll/HR systems such as Primula for numerous government and commercial tenants until phased restoration into March. Vendor post-mortems and independent analysis pointed to abuse of Cisco ASA VPN edge weaknesses (CVE-2023-20269 class issues) as the probable initial-access path leveraged by Akira affiliates.

Root cause

Ransomware deployment via compromised edge/VPN exposure on a shared Swedish data-center footprint

References