Miljödata
bd_e345fc7d3bc9eceb · schema v1 · pii pii-v1
Full breach record for Miljödata →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedCyberattack on Miljödata – Skellefteå Municipality warns. Miljödata: A cyberattack targeted the human resources management system of Miljödata, used by 80% of Swedish municipalities, which may have resulted in a leak of sensitive data. The affected municipalities, including Karlstad, Skellefteå, and Luleå, have activated crisis teams to manage the situation. The data protection authority, IMY, has received more than 70 notifications and is investigating the incident. Linked ransomware group: datacarry.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 24, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitedatacarrybd_6a42c7acbaaa0c2d2025-09-13 · +20dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
datacarry
According to ransomware.live, DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.