The Supplier Was Fined. Its Customers Are Still Under Investigation.
On 22 September Sweden's data protection authority, IMY, fined Miljodata i Karlskrona AB 1.8 million kronor for failing to protect personal data under Article 32(1) of the GDPR. The incident it concerns was disclosed on 25 August 2025, which BleepingComputer has also reported as the date of the attack; IMY dates the attack only to August 2025. Part of the stolen data was published on a dark web leak site the following month. IMY records that Miljodata's affected customers included a majority of Sweden's municipalities, several regions and government agencies, and a large number of private companies. IMY confirmed on 22 September 2026 that separate reviews of two municipalities and one region remain ongoing. When it opened those reviews in November 2025 it named them as the City of Gothenburg, Almhult Municipality and Region Vastmanland, and said they would focus particularly on those bodies' own processing of personal data inside Miljodata's systems: which categories of data were held, and about which people.
That emphasis is the whole briefing. The obvious lesson of a supplier breach is supplier due diligence, and it is not the one the regulator has put at the front of its customer reviews. IMY named three categories it would look at among others: people with protected identities, employees who had left long ago, and data about children. It has not said whether the customers' selection and oversight of their supplier also falls within scope, and we should not assume either way. What it has said is enough to be going on with. The attacker did not only steal from those bodies. The attacker published an inventory of what they had been keeping.
What happened
- 25 August 2025Miljodata discloses the incident. BleepingComputer has reported this date as both the disclosure and the attack; IMY dates the attack only to August 2025. The company supplies systems used by Swedish public bodies for human resources, occupational health and related functions, including sickness absence and rehabilitation records.
- 13 September 2025The group calling itself Datacarry publishes stolen data on its dark web portal. BleepingComputer reported a demand of 1.5 bitcoin, around $168,000 at the time, and a 224MB archive. It reports separately that Have I Been Pwned's copy of the leaked data contains names, email addresses, physical addresses, telephone numbers, government identity numbers and dates of birth. It also reported that the attack disrupted IT services in "over 200 regions", a count whose unit is unclear given Sweden has 21 regions and 290 municipalities, and named Halland, Gotland, Skelleftea, Kalmar, Karlstad and Monsteras among those affected.
- 3 November 2025IMY opens reviews of Miljodata and of three of its customers: the City of Gothenburg, Almhult Municipality and Region Vastmanland. IMY states that the customer reviews will focus on those bodies' own processing of personal data in Miljodata's systems, and in particular on what categories of data were processed and about which people, including people with protected identities, employees whose employment ended long ago, and data about children. IMY relays the Prosecution Authority's figure of over 1.5 million individuals whose data was published.
- 22 September 2026IMY issues its decision against Miljodata. A sanction fee of 1.8 million kronor for infringing Article 32(1). IMY concludes that the company's technical and organisational security was not at a sufficiently high level given the types of personal data it processed, and rests that conclusion on two specific shortcomings: it had not carried out sufficient checks when installing new software, and it had not implemented automated real-time monitoring of its systems to detect intrusion and suspicious activity. IMY assesses that the company acted negligently. According to the company, 2.2 million people were covered by the incident. The data categories named include personal identity numbers, contact details, sickness absence records, rehabilitation information and school incident reports.
- 22 September 2026In the same announcement IMY confirms that its reviews of two municipalities and one region remain ongoing. It says nothing further about their scope, their timing or whether penalties will follow.
Why this one is different
The regulator penalised the supplier and kept going, and not only in the direction you would expect. The usual reading of a supplier breach is that the customer's failure, if any, was one of oversight: it should have asked harder questions before signing. IMY may yet examine that. What it said it would look at first is something else, namely those bodies' own processing inside Miljodata's systems, what data they held and about whom. That exposure was not created by the breach; it was revealed by it. Our reading is that a supplier compromise therefore works as an unannounced audit of the customer's own data governance, one run by an attacker and delivered to a regulator, against which no contract clause offers any protection.
The categories IMY named are the ones nobody reconciles. People with protected identities. Employees who left long ago. Children. None is an obscure edge case, and all three are the predictable residue of an HR or occupational health system that has run for years without anyone auditing what is still in it. Ask a UK organisation which supplier holds records on employees who left more than six years ago, and the honest answer is usually that nobody has looked. That question is answerable this month, at no cost, and it is the question this decision is actually about.
The fine was never the exposure. A sanction of 1.8 million kronor against 2.2 million people is under one krona a head, and close in magnitude to what the attackers asked in ransom. There is a structural reason: Article 32 infringements sit in the GDPR's lower penalty tier, capped at 10 million euro or 2% of worldwide annual turnover, whichever is higher. The UK equivalent is 8.7 million pounds or 2%. A board that models supplier risk as "the supplier will be penalised and we will be made whole" is watching a line that was never going to move.
The security findings were ordinary, and that is the point. IMY concluded that the overall level of technical and organisational security was not high enough for the types of data processed, resting that on two shortcomings: sufficient checks were not carried out when installing new software, and automated real-time monitoring to detect intrusion and suspicious activity was absent. It assessed the conduct as negligent. Nothing there is exotic. Almost every supplier questionnaire asks whether a change management policy exists and whether monitoring is in place; almost none asks for the change record covering the most recent software installation into the environment holding your data, or the detection record showing what fired and who acted. A policy answers yes to both. Evidence is what the regulator assessed.
Concentration was the multiplier, and nobody owned it. IMY records that a majority of Sweden's municipalities were among the affected customers, alongside several regions, government agencies and many private companies. BleepingComputer separately reports that Miljodata supplies roughly 80% of Sweden's municipalities, which is a customer-base figure rather than a count of those affected. Either way, one Article 32 failure reached a substantial share of a country's public sector. No individual council decided that. Each made a defensible choice on price, fit and reference, and the concentration was the emergent result of hundreds of decisions taken separately. It is the shape of risk supplier registers are worst at showing, because a register ordered by criticality rates each entry on its own merits and never asks how many point at the same company.
The commercial exposure for UK organisations
Regulatory. UK GDPR reproduces the GDPR's structure. Article 32 binds controllers and processors alike, so a fine under it does not by itself settle who acted in which role, and IMY does not state the roles. What matters for a UK reader is that the controller's own obligations do not transfer with the system: Article 28(1) requires a controller to use only processors providing sufficient guarantees, a duty regulators have read as continuing through the life of the relationship rather than as a procurement-day test, and data minimisation and storage limitation apply to data placed in someone else's platform exactly as they do on your own servers.
Legislative. The Cyber Security and Resilience Bill is in House of Lords Committee stage from 1 September 2026, with Report stage scheduled for 26 October 2026. It brings managed service providers and data centre operators into regulation for the first time and creates a category of designated critical suppliers who, on designation, become directly regulated in their own right. Published summaries of the Bill describe a reporting requirement of 24 hours for initial notification and 72 hours for a full report. That matters here for a reason boards routinely miss: a 24 hour clock is in practice a supply chain clock. If your supplier takes three days to tell you what happened, your first 24 hours expired before you knew the clock had started. Notification terms drafted against the GDPR's 72 hour breach reporting window are already behind the direction of travel.
Financial. The direct costs land on the customer: notification at scale, legal advice, incident response, regulatory correspondence, and the cost of running the function without the system. Swedish public bodies lost access to human resources and occupational health processes while the supplier recovered. None of that is recoverable from a penalty paid by someone else to a regulator.
Contractual. Most processor agreements cap liability at a multiple of annual fees. For a system costing tens of thousands a year and holding records on hundreds of thousands of people, the cap and the exposure are not the same order of magnitude. Our own view, a commercial reading rather than a settled legal one, is that boards should not assume a regulatory fine levied on them as controller is recoverable from a processor as damages, and should take advice on that specific point.
Governance. Ask who owns supplier concentration in your organisation and the answer is usually an empty chair. Procurement owns cost and competition, the business owns the relationship, security owns the questionnaire. Nobody owns the arithmetic of how many of our people a single supplier failure would reach, and nobody owns the inventory of what we have put in each supplier's platform. Those are two different blind spots and this decision has opened both.
What leaders should do now
- Inventory what you have put in, not just who you bought from. For your top suppliers, list the categories of personal data you hold in their platform and the populations it covers. IMY named three that travel: people with protected identities, employees who left long ago, and children. If nobody can answer for your largest supplier this week, that is the finding, and you have found it before a regulator did.
- Produce a concentration list, not a criticality list. Rank suppliers by the number of data subjects a single failure at that supplier would reach. It is a different ordering from your criticality register, it is usually shorter, and it is the list this decision is about.
- Replace two questionnaire items with two evidence requests. For your three most concentrated suppliers, ask for the change record covering the most recent software installation into the environment holding your data, and the detection record for the last 90 days showing what monitoring fired and who acted. Those are the two shortcomings IMY identified. A supplier that cannot produce either has told you something a policy library cannot.
- Reset the notification clock in the contract. If your supplier notification term says 72 hours, it was drafted for GDPR breach reporting and it will not survive a 24 hour regulatory clock. Change it at renewal as standard, and change it now for the suppliers on the concentration list.
- Name an owner. One named executive, reporting two numbers to the board each quarter: the largest number of our people reachable through a single supplier failure, and the oldest record we are still holding in someone else's platform.
Three questions for the board
- For our largest supplier, what categories of personal data have we placed in their platform and about which populations, and when did anyone last look?
- Which single supplier failure would reach the largest number of our employees, customers or citizens, who approved that concentration, and when was it last reviewed?
- If a regulator asked us, as the Swedish regulator has asked two municipalities and a region, to account first for what we hold in a supplier's system rather than for how we vetted that supplier, what would we produce and how long would it take?
The strategic takeaway
The commercial case for supplier assurance is usually made as insurance against an event that might not happen. This decision offers a sharper version, and a different one from the one most readers will take away. Most of Sweden's municipalities bought a sensible system from a competent-looking supplier at a reasonable price. The supplier's security was found wanting on ordinary controls, its conduct assessed as negligent, and it paid 1.8 million kronor. Almost eleven months before that decision, the regulator had already opened reviews of three of its customers, and the first thing it said it would examine was not the supplier at all. It was what those organisations had put into the system and kept there.
The useful reading for a UK leadership team is not "vet your suppliers harder", though that remains true. It is that the data you place in a third party's platform stays your data, your minimisation problem and your retention problem, and that a breach there converts all three from private housekeeping into a public record. An organisation that can produce its concentration number, its data inventory and its notification terms on request is not only harder for a regulator to fault. It moves faster through enterprise procurement, where buyers now ask for the same artefacts, and presents better at insurance renewal and in diligence. That is one of the few compliance capabilities with a direct commercial return, which is why it should not sit unowned between procurement, legal and security.
Confidence note
Confirmed. From IMY's announcement of 22 September 2026: the 1.8 million kronor sanction fee on Miljodata i Karlskrona AB; the infringement of Article 32(1); the conclusion that the level of technical and organisational security was not high enough for the types of personal data processed, resting on two shortcomings, that sufficient checks were not carried out when installing new software and that automated real-time monitoring to detect intrusion and suspicious activity was not implemented; IMY's assessment that the company acted negligently; that according to the company 2.2 million people were covered by the incident; the data categories named; that a majority of Sweden's municipalities, several regions and government agencies and many private companies were among the affected customers; and that reviews of two municipalities and one region remain ongoing. From IMY's announcement of 3 November 2025: that the bodies under review are Miljodata, the City of Gothenburg, Almhult Municipality and Region Vastmanland; that the customer reviews focus on those bodies' own processing in Miljodata's systems, particularly which categories of data and about which people, including people with protected identities, long-departed employees and children; and the Prosecution Authority's figure of over 1.5 million individuals whose data was published. Fine and date corroborated by BleepingComputer, Computer Sweden and Sweden Herald, all 22 September 2026.
Reported. The date of 25 August 2025 and whether it marks the attack or the disclosure, the Datacarry attribution, the 1.5 bitcoin demand at around $168,000, publication on 13 September 2025, the 224MB archive and its contents, and the figure of roughly 80% of Swedish municipalities are from BleepingComputer, not IMY. That 80% describes Miljodata's customer base rather than the share affected, and BleepingComputer is itself inconsistent between "80% of Sweden's municipalities" and "80% of Sweden's municipal systems". Its separate figure of "over 200 regions" we quote rather than restate: Sweden has 21 regions and 290 municipalities, so the unit is unclear, and the bodies it names elsewhere mix the two. The $183,000 equivalent is a reported conversion that moves with the exchange rate. BleepingComputer also reports that Have I Been Pwned's copy of the leaked data corresponds to roughly 870,000 people, about half IMY's figure. No source we have read explains that gap. We have not reconciled 870,000, over 1.5 million and 2.2 million, and readers should not treat them as measuring the same thing.
Assessed. That Miljodata acts as processor and its customers as controllers is the ordinary reading of an arrangement of this kind, not a statement by IMY, which does not assign the roles. That the customer reviews are the commercially significant part of this decision, and that a supplier breach functions as an audit of the customer's own data governance, are our judgements. Our characterisation of what questionnaires ask, and of where ownership sits in most organisations, rests on commercial experience rather than a dataset. The Bill's parliamentary stages are as recorded on the UK Parliament bills pages and a scheduled Report stage can move; the 24 and 72 hour figures are from published summaries, and we have not confirmed them against the Bill text or established whether they sit on its face or in regulations to follow. That a 24 hour clock is in practice a supply chain clock is our inference. So is our gloss that the Article 28(1) duty is a continuing one rather than a procurement-day test, which follows regulatory guidance we have not cited here rather than the words of the Article. Our view on recovering regulatory fines from a processor is a commercial reading, not legal advice.
Not known. Whether Miljodata will appeal, and within what window, or whether IMY treats the matter as closed. The full reasoning of the decision, which we have read only through IMY's announcements and reporting of them. Whether the three customer reviews take in the customers' selection and oversight of their supplier as well as their own processing, and when they will conclude. Whether a penalty against a customer will follow. Miljodata's contractual liability position with its customers, and whether any civil claim has been brought.
What have you put in your largest supplier’s platform, and who last looked?
Garzon Cyber Solutions was built around the argument that security, compliance and the people who sustain them are one capability rather than three cost lines. A supplier data inventory, a concentration list and notification terms that survive a 24 hour clock are the same artefacts enterprise buyers, insurers and acquirers ask for. If your leadership team needs those built once, kept current and owned by someone named, start the conversation.
Start the Conversation →Integritetsskyddsmyndigheten (IMY), "Sanktionsavgift mot Miljödata för bristande säkerhet", 22 September 2026 · Integritetsskyddsmyndigheten (IMY), "IMY inleder granskningar utifrån Miljödata-läckan", 3 November 2025 · BleepingComputer, "Sweden fines Miljödata $183,000 over breach affecting 2.2 million", 22 September 2026 · Computer Sweden, "Miljödata får betala miljonavgift efter gigantiska läckan", 22 September 2026 · Sweden Herald, "Miljödata fined SEK 1.8 million after major data breach, Swedish watchdog says", 22 September 2026 · BleepingComputer, "Data breach at major Swedish software supplier impacts 1.5 million", 4 November 2025 · UK Parliament, "Cyber Security and Resilience (Network and Information Systems) Bill: Stages" · Information Commissioner's Office, "The maximum amount of a fine under the UK GDPR and the DPA 2018"
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification and specialist technology recruitment as one integrated capability for organisations in the UK, EU and Americas. We are a young firm and we publish our own research. Founder Jonathan Garzon spent his career selling cybersecurity, compliance and technology to security and technology buyers, working alongside marketing and technical colleagues, before building GCS around a single argument: delivered in the right order, security, compliance and the people to sustain them stop being three cost lines and become one commercial capability.