IMY, Sweden's privacy regulator, fined Miljödata SEK 1.8 million (about $183,000) on September 22 over the security failures behind a ransomware attack last year that exposed personal data on roughly 2.2 million people. Miljödata's HR and work-environment systems are used by around 80% of Swedish municipalities, and the compromised records included personal identity numbers, contact details, sick-leave and rehabilitation information, and records of school incidents involving minors.
IMY found that Miljödata breached Article 32 of the GDPR by failing to adequately test newly installed software and by not running automated real-time monitoring capable of detecting intrusions or suspicious activity. The attacker, using the name "Datacarry," had demanded a ransom of 1.5 bitcoin, worth about $168,000 at the time, and published the stolen data after Miljödata did not pay. The regulator said it has opened separate investigations into two municipalities and one region that used Miljödata's systems, meaning further penalties tied to the same breach may follow.
Comments
0 commentsNo comments yet — be the first.