Volvo North America reported a data breach affecting its employees after a ransomware attack targeted its third-party human resources software provider, Miljödata. The incident began on August 20, 2025, when Miljödata was compromised by the ransomware group DataCarry, which later claimed responsibility and published stolen data on its Tor leak site. Miljödata discovered the attack on August 23, 2025, and after an internal investigation, determined on September 2, 2025, that Volvo Group North America employee data had been impacted. The breach exposed sensitive personal information, including names and Social Security numbers, of current and former Volvo employees. According to notifications sent to affected individuals, Volvo’s own systems were not directly compromised; the breach was limited to data managed by Miljödata. The affected HR systems are used for managing medical certificates, rehabilitation, and work-related injury reporting, and the attack impacted at least 25 organizations, including major companies and hundreds of Swedish municipalities. The total number of affected Volvo employees has not been officially disclosed, but reports suggest it could be several thousand. The data breach notification service Have I Been Pwned indicated that the overall leak from Miljödata involved data from 870,000 accounts, though not all were necessarily Volvo employees. Impacted individuals are at risk of identity theft or fraud due to the exposure of their Social Security numbers. In response, Miljödata engaged cybersecurity experts, enhanced its hosted environment’s security, and is working to prevent future incidents. Volvo notified the Massachusetts Attorney General about the breach, fulfilling regulatory requirements. The breach highlights the risks associated with third-party vendors and the potential for widespread impact when such providers are compromised. Other organizations affected by the Miljödata attack include Scandinavian airline SAS and mining company Boliden. The incident underscores the importance of robust vendor risk management and timely breach notification procedures. DataCarry’s publication of the stolen data increases the urgency for affected individuals to monitor for misuse of their personal information. The breach has drawn attention to the need for improved security controls in HR software platforms used by large enterprises. Volvo’s transparency in communicating the breach to employees and authorities is a critical component of its incident response. The event serves as a reminder of the cascading effects a single ransomware attack on a service provider can have across multiple industries and organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting clarified the impact of the Volvo North America breach, stating that stolen employee information included Social Security numbers and other staff data. This added technical and impact detail to the previously disclosed supplier-linked breach.
Volvo North America disclosed that a data breach stemming from the ransomware attack on supplier Miljödata affected workforce personally identifiable information. Coverage indicates employee data was exposed as a result of the third-party compromise.
IT provider Miljödata was hit by a ransomware attack that compromised data belonging to customers, including information tied to Volvo North America. Reporting identifies the supplier attack as the root cause of the later Volvo-related breach disclosures.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcedarkreading.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.