Svenska kraftnät, Sweden’s state-owned power grid operator, confirmed a data breach after the Everest ransomware group claimed responsibility for stealing approximately 280 GB of internal data. The incident was limited to an external file transfer system and did not impact the country’s electricity supply or mission-critical systems. The company is collaborating with police and national cybersecurity authorities to assess the scope of the breach and determine what information may have been exposed, while refraining from attributing the attack until further confirmation is available.
Everest threatened to publish the stolen data unless its demands were met, posting the claim on its leak site. The group has previously claimed responsibility for attacks on other major organizations, though these claims have not always been independently verified. Svenska kraftnät’s Chief Information Security Officer emphasized that immediate action was taken and reassured the public that the electricity supply remains unaffected. The investigation is ongoing, and the company has not commented on the perpetrators or their motives at this stage.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Sweden’s power grid operator confirmed that it had suffered a data breach following the ransomware gang’s claim. This marked the organization’s official acknowledgment of the incident.
The Everest ransomware group publicly claimed it had breached Sweden’s power grid operator, Svenska kraftnät, and asserted it had stolen data from the organization. The claim was later echoed across multiple reports, but represents a single disclosure event.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.