3rd September 2025 Cyber Update: Swedish Municipalities Crippled by Supply Chain Ransomware Attack

A ransomware attack on IT supplier Miljödata has crippled services for over 200 Swedish municipalities, disrupting HR and healthcare systems. The attack highlights the severe risks of supply chain vulnerabilities in critical public infrastructure, with a police investigation underway.

3rd September 2025 Cyber Update: Swedish Municipalities Crippled by Supply Chain Ransomware Attack
Photo by Thom Reijnders / Unsplash
audio-thumbnail
Today’s Cyber Update
0:00
/118.883265

Cyber News Centre's cyber update for 3rd September 2025: Swedish IT supplier Miljödata has been hit by a ransomware attack, causing widespread disruption to over 200 municipalities and regional governments across the country.

Swedish Municipalities Crippled by Supply Chain Ransomware Attack

Miljödata provides essential HR and administrative software to approximately 80% of Sweden’s municipal governments. The company’s systems are used for managing sick leave, work-related injury reporting, and other critical employee data, making it a vital part of the country’s public sector infrastructure.

The Update and Why It Matters

The Update: A ransomware attack on Swedish IT supplier Miljödata has crippled essential services for over 200 of the country’s 290 municipalities. The breach, discovered on Saturday, August 23rd, has taken down critical HR and administrative systems used for managing sick leave, medical certificates, and occupational injury reports. Miljödata CEO Erik Hallén confirmed the attack on August 25th, stating that the intrusion had affected a significant portion of their client base. The attackers have reportedly demanded a ransom of 1.5 Bitcoin, to prevent the release of stolen data.

Swedish authorities, including the national CERT-SE and police, are investigating the incident. The full extent of the data breach is still being assessed, but regions like Gotland have warned that sensitive personal information may have been compromised. This incident follows a similar supply chain attack on Swedish IT provider Tietoevry last year, which also impacted government services.

Why it Matters: This attack on Miljödata is a stark reminder of the fragility of critical public infrastructure when it relies on centralized third-party suppliers. By targeting a single IT provider, the attackers were able to cause a cascading failure that has disrupted essential government functions across an entire nation.

The incident demonstrates that even a relatively small ransom demand can be leveraged to create widespread chaos, highlighting a shift in tactics that could see more frequent attacks on similar single points of failure. For governments and public sector organizations worldwide, this event serves as a critical warning to reassess their supply chain security and implement more robust contingency plans to ensure the continuity of essential services.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.