Article Details
Scrape Timestamp (UTC): 2025-08-27 18:26:24.859
Original Article Text
Click to Toggle View
IT system supplier cyberattack impacts 200 municipalities in Sweden. A cyberattack on Miljödata, an IT systems supplier for roughly 80% of Sweden’s municipal systems, has caused accessibility problems in more than 200 regions of the country. In addition to the service disruption, there are concerns that attackers also stole sensitive data. Local media report that the threat actor demanded a ransom of 1.5 (currently around $168,000) Bitcoins from Miljödata in exchange for not leaking stolen information. Miljödata is a Swedish software company that develops and provides work environment and HR management systems for municipalities, regions, and organizations. Its systems are used by the majority of municipalities in Sweden to handle medical certificates, rehabilitation cases, occupational injuries, incident and work environment reporting, and systematic work environment management (SAM). The attack occurred over the weekend, with Miljödata CEO Erik Hallén confirming on August 25 that more than 200 municipalities in Sweden have been impacted. “We are working very intensively together with external experts to investigate what has happened, what and who has been affected, and to restore system functionality,” stated Hallén. BleepingComputer was able to find announcements about the incident in the region of Halland Region, and also on Gotland Region, warning their citizens that “sensitive personal data may have been leaked.” Other municipalities reported as impacted by Swedish media are Skellefteå, Kalmar, Karlstad, and Mönsterås. Swedish minister for civil defence, Carl-Oskar Bohlin, stated on X that the incident is being evaluated to estimate its impact with the help of CERT-SE, and the police started an investigation. “The scope of the incident has not yet been clarified, and it is too early to determine the actual consequences,” stated the minister. At the time of writing, no ransomware groups have taken responsibility for the attack at Miljödata publicly. The company’s website is currently offline and attempts to contact them indicate that email servers are down. In January 2024, Swedish IT services and cloud hosting provider Tietoevry was hit by an Akira ransomware attack which impacted operations across a wide range of businesses and caused service outages on government organizations and universities. Picus Blue Report 2025 is Here: 2X increase in password cracking 46% of environments had passwords cracked, nearly doubling from 25% last year. Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.
Daily Brief Summary
A cyberattack targeted Miljödata, affecting over 200 municipalities in Sweden, disrupting critical IT services used for work environment and HR management.
The attackers demanded a ransom of 1.5 Bitcoins, approximately $168,000, threatening to leak sensitive data if not paid.
Miljödata's systems manage medical certificates, rehabilitation, and occupational injury reports, raising concerns over potential data breaches.
CEO Erik Hallén confirmed intensive efforts with external experts to investigate and restore system functionality.
Swedish authorities, including CERT-SE and the police, are assessing the incident's impact and have initiated an investigation.
The attack follows a previous ransomware incident in January 2024 involving Swedish IT services provider Tietoevry, indicating a trend in targeting critical infrastructure.
The incident has prompted heightened scrutiny on cybersecurity measures within Swedish municipal systems.