Swedish Data Protection Authority Fines Miljödata $183,000 Over 2.2 Million Person Breach
Regulator cites inadequate security measures in incident affecting August 2025

Key Takeaways
- IMY fined Miljödata $183,000 (SEK 1.8 million) for security failures leading to a breach.
- Approximately 2.2 million individuals were affected by the August 2025 incident.
- The penalty reflects the regulator's emphasis on organizational accountability for data protection.
- No specific CVE, malware, or exploitation vector was disclosed in connection with the breach.
- The fine was announced on September 22, 2026, several months after the breach occurred.
Quick answers
- What happened?
- The Swedish Authority for Privacy Protection (IMY) has levied a fine of $183,000 (SEK 1.8 million) against IT systems provider Miljödata following a data breach in August 2025 that exposed the personal information of approximately 2.2 million individuals. The decision underscores the regulator's focus on organizational accountability for data security failures.
- What should defenders do?
- Organizations should review and strengthen their technical and organizational security measures in accordance with applicable data protection regulations. Implementing robust access controls, encryption, and regular security assessments can help reduce the risk of regulatory penalties and data breaches.
The Swedish Authority for Privacy Protection (IMY) has imposed a fine of $183,000 (SEK 1.8 million) on Miljödata, an IT systems provider, for inadequate security measures that led to a data breach in August 2025. The incident affected approximately 2.2 million people. According to IMY, the fine was issued due to the organization's failure to implement appropriate technical and organizational measures to protect personal data. The regulator emphasized that such penalties serve as a deterrent and reinforce the obligations of data controllers under Swedish and EU data protection law. Miljödata has been notified of the decision. The breach occurred several months prior to the fine being announced in late September 2026. No specific exploitation vector, malware, or CVE was identified in the reporting; the fine relates to the organization's overall security posture rather than a discrete software vulnerability.
Security Details
The incident resulted from inadequate security measures as determined by the Swedish Authority for Privacy Protection (IMY). Specific technical details regarding the nature of the exposure, the data categories involved, or the attack vector were not disclosed in the source reporting.
Mitigation
Organizations should review and strengthen their technical and organizational security measures in accordance with applicable data protection regulations. Implementing robust access controls, encryption, and regular security assessments can help reduce the risk of regulatory penalties and data breaches.
Sources
BleepingComputer
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sep 22, 2026 · 21:40
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



