Miljödata, a major Swedish IT systems supplier serving approximately 80% of Sweden's municipalities, suffered a significant cyberattack in August that resulted in the exposure of personal data belonging to 1.5 million individuals. The attackers, identified as the Datacarry threat operation, stole sensitive information and demanded a ransom of 1.5 Bitcoin, subsequently leaking a 224 MB archive of data on the dark web. The breach affected citizens across multiple regions, including Halland, Gotland, Skellefteå, Kalmar, Karlstad, and Mönsterås, and included data from children, protected identity subjects, and former employees.
The Swedish Authority for Privacy Protection (IMY) and other state agencies, including CERT-SE and the police, launched immediate investigations into the incident, focusing on potential violations of the European Union's General Data Protection Regulation (GDPR). IMY is prioritizing its investigation on Miljödata and several municipalities, examining both the security measures in place and the handling of sensitive data. The incident has raised serious concerns about the adequacy of security controls and data management practices within Swedish public sector IT systems, prompting calls for improved safeguards to prevent similar breaches in the future.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned ingested a 224 MB archive attributed to DataCarry and added the Miljödata incident to its breach database. The service reported the leaked dataset contains personal information on about 870,000 individuals.
Sweden's Authority for Privacy Protection (IMY) began investigating the Miljödata cyberattack and dark web exposure for possible GDPR violations, including what personal data was stored and whether security shortcomings contributed to the breach. IMY said the exposed data may correspond to information on up to 1.5 million people.
The threat group Datacarry/DataCarry allegedly published data stolen from Miljödata on the dark web, escalating the incident from theft and extortion to public exposure of the dataset.
Following Miljödata's disclosure of the attack, Swedish police and CERT-SE started investigating because of the breach's broad impact on public-sector operations and data.
In August 2025, Swedish municipal IT supplier Miljödata was hit by a cyberattack in which attackers stole data and demanded 1.5 Bitcoin to prevent its release. The incident also caused operational disruptions across multiple Swedish regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.