Data Breach Defined in Plain Terms
A data breach is a security failure that exposes information to people who should not have it. Under GDPR Article 4(12) a personal data breach is any breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data or unauthorised access to it. Theft is one route. Error is another.
That definition is broader than most people expect. A misdirected email with a staff list attached is a personal data breach. So is a lost unencrypted USB stick, a ransomware attack that destroys records and a supplier leaking your employee files.
The volume in Sweden is rising fast. The Swedish data protection authority IMY received 12,276 personal data breach notifications in 2025, the highest number since GDPR began to apply in 2018 and an increase of almost 90 percent on the year before. IMY attributes much of that rise to intrusions at suppliers that serve many organisations at once.
For a Swedish municipality, a hospital or a mid-sized company, this has stopped being an abstract risk. It is now a question of which supplier holds your employee records and what happens on the night someone gets into it.
How Data Breaches Happen
A breach is rarely one dramatic moment. It is a sequence and every step in it gives a defender a chance to intervene.
- Get in: A stolen or reused password, a phishing email, an unpatched internet-facing system or a weakness in a web application.
- Move: Use that first account to reach systems holding more than it should be able to see.
- Find: Locate where the personal data actually lives and stage it for copying.
- Take: Copy the data out usually over hours or days.
- Monetise: Demand a ransom, publish the data on a leak site or sell it.

The middle of that sequence is where breaches are won and lost. Attackers are typically inside for a while before anything leaves which is time an organisation can use if someone is watching and has the authority to act.
Three shifts made this easier for attackers. Working credentials are traded in bulk so an intruder often starts with a login rather than an exploit. Extortion has been industrialised with leak sites, affiliates and negotiators. And organisations have concentrated their data in shared platforms so a single intrusion can reach hundreds of customers at once.
Types of Data Breaches
European regulators classify breaches by the kind of loss involved. The EDPB guidance on breach notification names three.
- Confidentiality Breach: Personal data is disclosed to or accessed by someone with no authorisation.
- Integrity Breach: Personal data is altered without authorisation.
- Availability Breach: Access to personal data is lost or the data is destroyed.
One incident can be all three at once. Ransomware that copies records, encrypts them and then publishes them hits every category in a single night.
Sorted by cause, the routes a Swedish organisation is most likely to meet are these.
- Stolen Credentials: A working password bought or phished, then used on a service that has no second factor.
- Phishing and Social Engineering: A person is persuaded to open, approve or send something.
- Supplier Compromise: Your data leaks from a system you do not run alongside data from every other customer.
- Exposed Systems and Misconfiguration: A database, storage bucket or admin panel reachable from the internet without protection.
- Web Application Weaknesses: A flaw in a public-facing site used to reach the data behind it.
- Ransomware with Extortion: Data copied before encryption, then used as leverage.
- Insider Isuse: Someone with legitimate access taking or looking at what they should not.
- Human Error: The wrong recipient, the wrong attachment, the wrong permissions on a shared folder.
That last group is easy to underrate. In the incident data the UK regulator publishes, more than three quarters of reported personal data breaches are classed as non-cyber and the single most common cause is personal data emailed to the wrong recipient.
The Business Impact of a Data Breach
Search for the average cost of a data breach and you will find one confident global number usually several million dollars. Treat it carefully. It comes from vendor-sponsored research based on a sample of large organisations. It tells a Swedish municipality with 900 employees very little.
Official statistics show a different shape. In the UK government’s Cyber Security Breaches Survey for 2025/2026, published on 30 April 2026, 43 percent of businesses identified a breach or attack in the previous year. The median perceived cost of the most disruptive one was zero pounds with most falling between zero and £200.
Those are perceived costs across all breaches and attacks, most of them phishing so they are not audited losses. Even so the shape is clear. Most incidents cost little and a small number cost enormously. UnitedHealth Group reported around 3 billion dollars of cyberattack-related costs during 2024 after the Change Healthcare breach.
Fines are the part organisations plan for and misjudge. A security failure under GDPR Article 32 sits in the lower penalty tier of Article 83(4), capped at €10 million or 2 percent of worldwide annual turnover whichever is higher.
That is still a serious number and regulators are using it. IMY set a sanction fee of SEK 6 million against Sportadmin in January 2026. The UK regulator fined Capita £14 million in October 2025 reduced from a proposed £45 million.
The fine is rarely the largest line. The rest of the bill looks like this.
- Notification and Support: Writing to every affected person, staffing a helpline and often funding identity monitoring.
- Investigation and Recovery: Forensics, legal advice, rebuilding systems and rotating every credential.
- Disruption: Services offline or run on paper while systems are restored.
- Harm to Individuals: Targeted fraud, identity theft and genuine danger where protected identities are exposed.
- Procurement and Trust: Every future tender asking harder questions and expecting answers that can be evidenced.
Real-World Data Breach Cases
Four breaches, four different failures. In each one the investigating authority named the control that was missing.
Sportadmin: The Alarm That Did Not Sound
In January 2025 an attacker reached Sportadmin, a Swedish platform used by sports clubs for membership and communication through a weakness in its website. Data on more than 2.1 million people was taken and later published on the darknet after a ransom demand was refused.
Most of it concerned children and young people. Names, personal identity numbers, contact details, club and sport some health information and some protected identities all appeared in the leak.
IMY’s decision of 26 January 2026 is unusually specific about what went wrong. The monitoring system raised no alarm during the intrusion. The alarm came two days later when a server crashed. Accounts carried more privileges than they needed and known weaknesses had been left unaddressed. IMY found a breach of GDPR Article 32 and set a sanction fee of SEK 6 million.
The control IMY pointed to is an ordinary one. See an intrusion while it is happening and act on it the same hour.

Miljödata: One Supplier, 164 Municipalities
On Saturday 23 August 2025 attackers reached the IT environment of Miljödata, a system supplier whose HR and administrative software is used widely across Swedish municipalities. The company disclosed the attack two days later. A ransom was demanded and refused. In mid-September the stolen data was published on the darknet by a group calling itself Datacarry.
IMY received around 250 breach notifications from this single incident with at least 164 municipalities and four regions affected. The Swedish Prosecution Authority confirmed that data on more than 1.5 million people had been published. Much of it came from the Adato system which handles sick leave, rehabilitation and occupational injuries so the exposure landed on current and former employees.
On 3 November 2025 IMY opened investigations into Miljödata and three of its public-sector customers examining security measures on one side and, on the other, what data those organisations had placed in a supplier’s system at all. Particular attention went to children’s data, protected identities and former employees. That second question is the lesson here. Data you no longer need cannot leak.
Capita: A 10-Minute Alert and a 58-Hour Response
In March 2023 a malicious file landed on an employee device at Capita, a UK outsourcing group. A high-priority security alert fired within 10 minutes. The device was not isolated for 58 hours, against the company’s own one-hour target. The attacker used that window to move through the network and remove data.
Personal data belonging to 6.6 million people was taken including members of more than 300 pension schemes. The UK regulator found the security operations function understaffed and missing its alert-response targets for the six months before the attack. It issued a £14 million fine in October 2025.
The alert did its job. Nobody acted on it for two and a half days.
Change Healthcare: One Portal Without MFA
In February 2024 attackers used stolen credentials to log into a remote-access portal at Change Healthcare, a payments processor sitting in the middle of the US health system. The portal had no multi-factor authentication. The chief executive of its parent company confirmed that in testimony to Congress a few months later.
The breach was reported to the US health regulator as affecting 192.7 million people, the largest health data breach that regulator has recorded. A password was the only control on the door.
Data Breaches and Compliance in Sweden
A Swedish organisation that suffers a breach is usually running two reporting clocks at once. Each one is set by a different law.
GDPR: Article 33 requires you to notify IMY within 72 hours of becoming aware of a personal data breach unless it is unlikely to result in a risk to the people affected. Article 34 requires you to tell those people without undue delay where the risk to them is high.
Article 33(5) requires you to record every breach internally including the ones you decide not to report. More detail sits on our GDPR compliance page.
Cybersäkerhetslagen: if your organisation falls under Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026, a significant incident carries its own cascade. An early warning within 24 hours, an incident report within 72 hours and a final report within one month.
Those reports go through the Cyberportalen service run by MCF (formerly MSB) and are received by CERT-SE at the National Cyber Security Centre, which passes them to your supervisory authority. The first version of that reporting tool opened on 1 July 2026. See our NIS2 Sweden hub for scope and obligations.
Board accountability: NIS2 Article 20 makes the management body responsible for approving and overseeing security measures. Supervisory authorities can hold board members personally accountable. Article 21.2d covers supply-chain security and Article 21.2g covers security awareness training which are the two obligations the Swedish cases speak to most directly.
Financial entities: DORA Article 17 requires an ICT incident management process supervised in Sweden by Finansinspektionen. Firms in scope should read our DORA compliance page. Organisations building a management system around these duties will find the structure on our ISO 27001 page.
One practical warning. The GDPR clock starts when you become aware of the breach not when your investigation is finished. Article 33 allows you to notify in phases and provide detail later. Waiting for a complete picture is how organisations miss the deadline.
How to Spot a Data Breach
Some signals come from your own systems.
- A login from an unusual country or at an unusual hour on an account that never travels.
- Large volumes of data moving to an external destination outside normal patterns.
- New accounts or new privileges that nobody requested.
- Security tooling or logging switched off on a server.
- A system slowing down or crashing without an obvious cause.
Others arrive from outside which is how a great many organisations find out.
- A customer, journalist or researcher tells you your data is being offered for sale.
- Your organisation appears on an extortion leak site.
- A supplier notifies you that their environment was breached.
- Staff start receiving phishing that knows too much about internal detail.
Now the uncomfortable part. Sportadmin had monitoring and it stayed silent through the intrusion. Capita’s monitoring alarmed in 10 minutes and the compromised device stayed connected for 58 hours. Detection without a response path is not detection.
Decide today who is allowed to isolate a server at 02:00 on a Saturday without asking anyone first. Write the name down. As a cheap first look at exposure already in circulation, a domain breach checker will tell you whether credentials tied to your domain appear in known leaks.
How to Prevent a Data Breach
Data breach prevention is mostly a small number of controls applied without exceptions. Start with the technology.
- Require multi-factor authentication on every service reachable from the internet, including remote access, VPN and legacy portals inherited through acquisitions.
- Give every account the least access it needs and review privileges on a fixed schedule.
- Patch internet-facing systems and web applications before anything else.
- Encrypt personal data at rest and on anything portable.
- Keep logs somewhere an attacker who owns the server cannot delete them.

Then the process which is where the Swedish cases were decided.
- Put someone on the alarm around the clock and give that person written authority to isolate a machine without convening a meeting.
- Delete data you no longer need. Set retention periods for HR records, former employees and anything concerning children then enforce them in the supplier’s system as well as your own.
- Ask every supplier what they hold about your people where it sits and how fast they will tell you if it leaks. Put the answer in the contract.
- Write the incident plan with both reporting clocks in it and rehearse it once a year with the people who would actually be woken up.
- Keep offline backups and test a restore at least once a year.
Finally the people who are involved in most breaches and are also the fastest detection system you have.
- Train staff on phishing and on the ordinary breaches too, the misdirected email and the wrong attachment.
- Make reporting a mistake fast and blameless because the cost of a breach is set by how quickly it is contained.
- Run security awareness training as a routine rather than an annual slide deck.
- Test the technical side with penetration testing before an attacker does.
None of this is advanced. Every failure in the four cases above was later described by a regulator as a basic control. Start with multi-factor authentication and with deleting data you no longer need. They cost the least and they take the most out of the blast radius.