Miljödata Work Environment & HR Systems Breach: DataCarry Ransomware Attack Exposes 2.2 Million Records, Results in $183,000 Fine

Miljödata Work Environment & HR Systems Breach: DataCarry Ransomware Attack Exposes 2.2 Million Records, Results in $183,000 Fine

Executive Summary

On August 25, 2025, Miljödata, a leading Swedish provider of work environment and HR management systems, experienced a significant ransomware and data extortion attack attributed to the DataCarry group. The breach disrupted IT services across more than 200 Swedish regions and compromised sensitive data belonging to 2.2 million individuals, including personal identity numbers, contact details, sickness absence records, rehabilitation records, and school incident reports. The attacker demanded a ransom of 1.5 Bitcoin (approximately $168,000 at the time), and upon non-payment, published the stolen data on the dark web. Following an investigation, the Swedish Data Protection Authority (IMY) fined Miljödata SEK 1.8 million (about $183,000) for failing to implement adequate technical and organizational security measures as required by Article 32(1) of the General Data Protection Regulation (GDPR). The incident highlights the critical importance of robust security controls, especially for public sector IT providers handling sensitive personal and health data.

Technical Information

The attack on Miljödata was executed by the DataCarry ransomware group, first observed in May 2025. The group infiltrated Miljödata’s internal network, exfiltrated confidential data, and encrypted critical systems. The attack followed a double-extortion model: after exfiltrating sensitive data, the threat actor demanded a ransom for decryption and threatened to release the data publicly if the ransom was not paid. When Miljödata refused to pay, the stolen data was published on a Tor-hosted leak site operated by DataCarry.

The Swedish Data Protection Authority (IMY) investigation found that Miljödata lacked sufficient checks on newly installed software and did not have automated, real-time monitoring for intrusions and suspicious activity. These deficiencies likely facilitated the initial access and lateral movement within the network. The attack not only affected Miljödata but also impacted approximately 200 Swedish municipalities, 25 private companies (including SAS and Boliden), and organizations such as Lund University and Volvo North America, demonstrating a significant supply chain impact.

The specific ransomware strain or malware family used in the attack has not been publicly disclosed. However, the tactics employed by DataCarry are consistent with contemporary ransomware operations, including network infiltration, data exfiltration, and system encryption. No technical indicators of compromise (IOCs) such as hashes, domains, or Bitcoin addresses have been published in available sources.

DataCarry is a newly identified ransomware and data extortion group, first observed in May 2025. Since its emergence, the group has claimed victims across multiple industries—including insurance, healthcare, real estate, retail, and aerospace—in countries such as Latvia, Belgium, Türkiye, South Africa, Switzerland, Denmark, and the United Kingdom. The Miljödata incident is one of the earliest and most significant attacks attributed to DataCarry, demonstrating their focus on high-value, data-rich targets and supply chain vulnerabilities.

The attack methods observed in this incident can be mapped to the following MITRE ATT&CK techniques (with confidence levels based on available evidence):

Initial Access may have involved exploiting public-facing applications (T1190) or the use of valid accounts (T1078) if credentials were compromised. Execution likely involved command and scripting interpreters (T1059), as is typical in ransomware deployments. Persistence could have been achieved through boot or logon autostart execution (T1547). Privilege escalation may have involved exploitation for privilege escalation (T1068) if unpatched systems were present. Defense evasion likely included impairing defenses (T1562), exploiting the lack of monitoring. Credential access may have involved OS credential dumping (T1003) for lateral movement. Discovery likely included file and directory discovery (T1083) to identify data for exfiltration. Lateral movement may have used remote services (T1021). Collection likely involved automated collection (T1119) for mass data theft. Exfiltration probably occurred over a command and control channel (T1041). Impact was confirmed through data encryption for impact (T1486), and may have included inhibiting system recovery (T1490) and stopping services (T1489).

Attribution to the DataCarry ransomware group is assessed with high confidence based on public claims, leak site postings, and consistent reporting across multiple sources. Attribution to a specific malware or tool is low confidence due to the lack of technical artifacts. Mapping to MITRE ATT&CK techniques is medium confidence, based on observed behaviors and regulatory findings.

Affected Versions & Timeline

The breach occurred on August 25, 2025, affecting Miljödata’s work environment and HR management systems, which are used by approximately 80% of Sweden’s municipalities. The attack disrupted IT services in over 200 regions and impacted both public and private sector organizations. The threat actor demanded a ransom of 1.5 Bitcoin (valued at $168,000 at the time). When the ransom was not paid, the stolen data was published on the dark web under the alias “Datacarry.” The Swedish Data Protection Authority (IMY) launched an investigation in November 2025 and concluded its findings on September 22, 2026, imposing a fine of SEK 1.8 million (approximately $183,000) on Miljödata for failing to implement adequate security measures. Ongoing investigations into two municipalities and one region affected by the breach were also announced.

Threat Activity

The DataCarry ransomware group is a newly identified threat actor, first observed in May 2025. The group employs a double-extortion model, exfiltrating sensitive data and threatening public release if ransom demands are not met. DataCarry has targeted organizations across multiple sectors and countries, with the Miljödata incident representing a significant supply chain attack affecting public sector IT systems and their downstream clients. The group’s tactics include network infiltration, data exfiltration, and system encryption, followed by ransom demands and public data leaks via a Tor-hosted site. The rapid expansion and international reach of DataCarry indicate a highly organized and capable threat actor.

Mitigation & Workarounds

The following mitigation actions are prioritized by severity:

Critical: Organizations using Miljödata or similar HR and work environment management systems should immediately review and enhance their technical and organizational security measures. This includes implementing automated, real-time monitoring for intrusions and suspicious activity, and conducting thorough checks on all newly installed software.

High: Conduct a comprehensive review of supply chain security, ensuring that all third-party providers adhere to robust security standards and are regularly audited for compliance. Ensure that all systems are patched and up to date to reduce the risk of exploitation.

Medium: Provide security awareness training to staff, focusing on phishing, credential theft, and ransomware prevention. Establish and regularly test incident response plans, including procedures for ransomware and data extortion scenarios.

Low: Monitor regulatory advisories and threat intelligence feeds for updates related to DataCarry and similar ransomware groups. Maintain regular backups and ensure they are stored offline or in immutable storage to facilitate recovery in the event of an attack.

Indicators of Compromise

The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. At the time of writing, no technical indicators of compromise (such as hashes, IP addresses, or Bitcoin wallets) specific to the Miljödata breach have been publicly disclosed. The only observable indicators are related to reporting and news domains:

Type

Indicator

Reported (date)

Source

 

Domain

ground[.]news

September 22-23, 2026

https://ground.news/article/environmental-data-fined-18-million-after-leak

Domain

www[.]mlex[.]com

September 22, 2026

https://www.mlex.com/mlex/amp/articles/2528214

URL

hxxps://ground[.]news/article/environmental-data-fined-18-million-after-leak

September 22-23, 2026

https://ground.news/article/environmental-data-fined-18-million-after-leak

URL

hxxps://www[.]mlex[.]com/mlex/amp/articles/2528214

September 22, 2026

https://www.mlex.com/mlex/amp/articles/2528214

No malware hashes, C2 infrastructure, or Bitcoin addresses have been published in connection with this incident.

References

https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/ (Published: September 22, 2026)

https://www.mlex.com/mlex/amp/articles/2528214 (Published: September 22, 2026)

https://ground.news/article/environmental-data-fined-18-million-after-leak (Published: September 22-23, 2026)

https://www.teiss.co.uk/news/datacarry-ransomware-group-breaches-swedish-it-company-miljodata-steals-confidential-data-16492

https://attack.mitre.org/

About Rescana

Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their supply chain. Our platform enables continuous evaluation of vendor security posture, supports regulatory compliance efforts, and delivers actionable insights for mitigating risks associated with third-party providers. For questions or further information, contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.