2024 Tietoevry — Akira ransomware in Swedish hosting DC; Primula and public-sector customer outages
Data compromised
Customer-operational datasets across tenant environments—population accounting dispersed across Swedish agencies and enterprises rather than one consumer numerator
Technical writeup
Finnish IT services giant Tietoevry confirmed a January 2024 encryption-and-extortion event confined to colocated infrastructure in Sweden, knocking payroll/HR systems such as Primula for numerous government and commercial tenants until phased restoration into March. Vendor post-mortems and independent analysis pointed to abuse of Cisco ASA VPN edge weaknesses (CVE-2023-20269 class issues) as the probable initial-access path leveraged by Akira affiliates.
Root cause
Ransomware deployment via compromised edge/VPN exposure on a shared Swedish data-center footprint
References
- https://www.tietoevry.com/en/newsroom/all-news-and-releases/press-releases/2024/01/tietoevry-ransomware-attack-in-sweden--restoration-work-progressing/
- https://www.tietoevry.com/en/newsroom/all-news-and-releases/press-releases/2024/04/tietoevry-conclusions-on-the-ransomware-attack/
- https://securityaffairs.com/158031/cyber-crime/tietoevry-akira-ransomware-attack.html