← Volvo Group

2025 Volvo Group North America — Miljödata ransomware supply chain; employee names & SSNs in Mass. AG filings

2025 Unknown records affected Share on X

Data compromised

HR-case-management style PII including government identifiers per Volvo NA letters

Technical writeup

Swedish HR/rehab outsourcer Miljödata fell to DataCarry ransomware in August–September 2025, exfiltrating multi-tenant datasets later mirrored on criminal leak blogs and Have I Been Pwned. SecurityWeek noted Volvo Group North America warned workforce members that names and Social Security numbers sat inside compromised Adato/Novi SaaS modules; a model notification uploaded to the Massachusetts AG docket anchors the US regulatory paper trail. Over 20+ private companies and ~200 Swedish municipalities shared fallout, so Volvo-specific counts stayed bundled inside broader Miljödata statistics.

Root cause

Ransomware and mass exfiltration against shared HR/rehab SaaS provider

References