Threats & attacks

What is a Data Breach

What counts as a data breach, what one actually costs, how Sweden's two reporting clocks work and the controls that stop one.

Key takeaways
  • A data breach is any security failure that exposes, alters or destroys personal data, whether the cause is an attacker or a mistake.
  • IMY received 12,276 personal data breach notifications in 2025, the highest since GDPR applied and almost 90 percent up on 2024.
  • Sweden’s two largest recent cases both ran through software suppliers. The Miljödata attack affected at least 164 municipalities and four regions.
  • Regulators judge the state of your security, whatever the attacker did. Being the target of a crime does not excuse an Article 32 failure.
  • A security failure under GDPR Article 32 carries a ceiling of €10 million or 2 percent of worldwide annual turnover, whichever is higher.
  • IMY set a SEK 6 million sanction fee against Sportadmin in January 2026 for missing real-time detection and excessive account privileges.
  • At Capita the alert fired in 10 minutes, the device stayed online for 58 hours and data on 6.6 million people was taken.
  • Sweden runs two reporting clocks, 72 hours to IMY under GDPR and a 24-hour, 72-hour and one-month cascade under Cybersäkerhetslagen.
  • More than three quarters of the personal data breaches reported to the UK regulator are non-cyber, most often an email sent to the wrong recipient.
  • Multi-factor authentication, least privilege and deleting data you no longer need remove the most risk for the least money.

Data Breach Defined in Plain Terms

A data breach is a security failure that exposes information to people who should not have it. Under GDPR Article 4(12) a personal data breach is any breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data or unauthorised access to it. Theft is one route. Error is another.

That definition is broader than most people expect. A misdirected email with a staff list attached is a personal data breach. So is a lost unencrypted USB stick, a ransomware attack that destroys records and a supplier leaking your employee files.

The volume in Sweden is rising fast. The Swedish data protection authority IMY received 12,276 personal data breach notifications in 2025, the highest number since GDPR began to apply in 2018 and an increase of almost 90 percent on the year before. IMY attributes much of that rise to intrusions at suppliers that serve many organisations at once.

For a Swedish municipality, a hospital or a mid-sized company, this has stopped being an abstract risk. It is now a question of which supplier holds your employee records and what happens on the night someone gets into it.

How Data Breaches Happen

A breach is rarely one dramatic moment. It is a sequence and every step in it gives a defender a chance to intervene.

  • Get in: A stolen or reused password, a phishing email, an unpatched internet-facing system or a weakness in a web application.
  • Move: Use that first account to reach systems holding more than it should be able to see.
  • Find: Locate where the personal data actually lives and stage it for copying.
  • Take: Copy the data out usually over hours or days.
  • Monetise: Demand a ransom, publish the data on a leak site or sell it.
How Data Breaches Happen

The middle of that sequence is where breaches are won and lost. Attackers are typically inside for a while before anything leaves which is time an organisation can use if someone is watching and has the authority to act.

Three shifts made this easier for attackers. Working credentials are traded in bulk so an intruder often starts with a login rather than an exploit. Extortion has been industrialised with leak sites, affiliates and negotiators. And organisations have concentrated their data in shared platforms so a single intrusion can reach hundreds of customers at once.

Types of Data Breaches

European regulators classify breaches by the kind of loss involved. The EDPB guidance on breach notification names three.

  • Confidentiality Breach: Personal data is disclosed to or accessed by someone with no authorisation.
  • Integrity Breach: Personal data is altered without authorisation.
  • Availability Breach: Access to personal data is lost or the data is destroyed.

One incident can be all three at once. Ransomware that copies records, encrypts them and then publishes them hits every category in a single night.

Sorted by cause, the routes a Swedish organisation is most likely to meet are these.

  • Stolen Credentials: A working password bought or phished, then used on a service that has no second factor.
  • Phishing and Social Engineering: A person is persuaded to open, approve or send something.
  • Supplier Compromise: Your data leaks from a system you do not run alongside data from every other customer.
  • Exposed Systems and Misconfiguration: A database, storage bucket or admin panel reachable from the internet without protection.
  • Web Application Weaknesses: A flaw in a public-facing site used to reach the data behind it.
  • Ransomware with Extortion: Data copied before encryption, then used as leverage.
  • Insider Isuse: Someone with legitimate access taking or looking at what they should not.
  • Human Error: The wrong recipient, the wrong attachment, the wrong permissions on a shared folder.

That last group is easy to underrate. In the incident data the UK regulator publishes, more than three quarters of reported personal data breaches are classed as non-cyber and the single most common cause is personal data emailed to the wrong recipient.

The Business Impact of a Data Breach

Search for the average cost of a data breach and you will find one confident global number usually several million dollars. Treat it carefully. It comes from vendor-sponsored research based on a sample of large organisations. It tells a Swedish municipality with 900 employees very little.

Official statistics show a different shape. In the UK government’s Cyber Security Breaches Survey for 2025/2026, published on 30 April 2026, 43 percent of businesses identified a breach or attack in the previous year. The median perceived cost of the most disruptive one was zero pounds with most falling between zero and £200.

Those are perceived costs across all breaches and attacks, most of them phishing so they are not audited losses. Even so the shape is clear. Most incidents cost little and a small number cost enormously. UnitedHealth Group reported around 3 billion dollars of cyberattack-related costs during 2024 after the Change Healthcare breach.

Fines are the part organisations plan for and misjudge. A security failure under GDPR Article 32 sits in the lower penalty tier of Article 83(4), capped at €10 million or 2 percent of worldwide annual turnover whichever is higher.

That is still a serious number and regulators are using it. IMY set a sanction fee of SEK 6 million against Sportadmin in January 2026. The UK regulator fined Capita £14 million in October 2025 reduced from a proposed £45 million.

The fine is rarely the largest line. The rest of the bill looks like this.

  • Notification and Support: Writing to every affected person, staffing a helpline and often funding identity monitoring.
  • Investigation and Recovery: Forensics, legal advice, rebuilding systems and rotating every credential.
  • Disruption: Services offline or run on paper while systems are restored.
  • Harm to Individuals: Targeted fraud, identity theft and genuine danger where protected identities are exposed.
  • Procurement and Trust: Every future tender asking harder questions and expecting answers that can be evidenced.

Real-World Data Breach Cases

Four breaches, four different failures. In each one the investigating authority named the control that was missing.

Sportadmin: The Alarm That Did Not Sound

In January 2025 an attacker reached Sportadmin, a Swedish platform used by sports clubs for membership and communication through a weakness in its website. Data on more than 2.1 million people was taken and later published on the darknet after a ransom demand was refused.

Most of it concerned children and young people. Names, personal identity numbers, contact details, club and sport some health information and some protected identities all appeared in the leak.

IMY’s decision of 26 January 2026 is unusually specific about what went wrong. The monitoring system raised no alarm during the intrusion. The alarm came two days later when a server crashed. Accounts carried more privileges than they needed and known weaknesses had been left unaddressed. IMY found a breach of GDPR Article 32 and set a sanction fee of SEK 6 million.

The control IMY pointed to is an ordinary one. See an intrusion while it is happening and act on it the same hour.

<!-- wp:heading {"anchor":"cases"} -->
<h2 id="cases" class="wp-block-heading">Real-World Data Breach Cases</h2>
<!-- /wp:heading -->

Miljödata: One Supplier, 164 Municipalities

On Saturday 23 August 2025 attackers reached the IT environment of Miljödata, a system supplier whose HR and administrative software is used widely across Swedish municipalities. The company disclosed the attack two days later. A ransom was demanded and refused. In mid-September the stolen data was published on the darknet by a group calling itself Datacarry.

IMY received around 250 breach notifications from this single incident with at least 164 municipalities and four regions affected. The Swedish Prosecution Authority confirmed that data on more than 1.5 million people had been published. Much of it came from the Adato system which handles sick leave, rehabilitation and occupational injuries so the exposure landed on current and former employees.

On 3 November 2025 IMY opened investigations into Miljödata and three of its public-sector customers examining security measures on one side and, on the other, what data those organisations had placed in a supplier’s system at all. Particular attention went to children’s data, protected identities and former employees. That second question is the lesson here. Data you no longer need cannot leak.

Capita: A 10-Minute Alert and a 58-Hour Response

In March 2023 a malicious file landed on an employee device at Capita, a UK outsourcing group. A high-priority security alert fired within 10 minutes. The device was not isolated for 58 hours, against the company’s own one-hour target. The attacker used that window to move through the network and remove data.

Personal data belonging to 6.6 million people was taken including members of more than 300 pension schemes. The UK regulator found the security operations function understaffed and missing its alert-response targets for the six months before the attack. It issued a £14 million fine in October 2025.

The alert did its job. Nobody acted on it for two and a half days.

Change Healthcare: One Portal Without MFA

In February 2024 attackers used stolen credentials to log into a remote-access portal at Change Healthcare, a payments processor sitting in the middle of the US health system. The portal had no multi-factor authentication. The chief executive of its parent company confirmed that in testimony to Congress a few months later.

The breach was reported to the US health regulator as affecting 192.7 million people, the largest health data breach that regulator has recorded. A password was the only control on the door.

Data Breaches and Compliance in Sweden

A Swedish organisation that suffers a breach is usually running two reporting clocks at once. Each one is set by a different law.

GDPR: Article 33 requires you to notify IMY within 72 hours of becoming aware of a personal data breach unless it is unlikely to result in a risk to the people affected. Article 34 requires you to tell those people without undue delay where the risk to them is high.

Article 33(5) requires you to record every breach internally including the ones you decide not to report. More detail sits on our GDPR compliance page.

Cybersäkerhetslagen: if your organisation falls under Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026, a significant incident carries its own cascade. An early warning within 24 hours, an incident report within 72 hours and a final report within one month.

Those reports go through the Cyberportalen service run by MCF (formerly MSB) and are received by CERT-SE at the National Cyber Security Centre, which passes them to your supervisory authority. The first version of that reporting tool opened on 1 July 2026. See our NIS2 Sweden hub for scope and obligations.

Board accountability: NIS2 Article 20 makes the management body responsible for approving and overseeing security measures. Supervisory authorities can hold board members personally accountable. Article 21.2d covers supply-chain security and Article 21.2g covers security awareness training which are the two obligations the Swedish cases speak to most directly.

Financial entities: DORA Article 17 requires an ICT incident management process supervised in Sweden by Finansinspektionen. Firms in scope should read our DORA compliance page. Organisations building a management system around these duties will find the structure on our ISO 27001 page.

One practical warning. The GDPR clock starts when you become aware of the breach not when your investigation is finished. Article 33 allows you to notify in phases and provide detail later. Waiting for a complete picture is how organisations miss the deadline.

How to Spot a Data Breach

Some signals come from your own systems.

  • A login from an unusual country or at an unusual hour on an account that never travels.
  • Large volumes of data moving to an external destination outside normal patterns.
  • New accounts or new privileges that nobody requested.
  • Security tooling or logging switched off on a server.
  • A system slowing down or crashing without an obvious cause.

Others arrive from outside which is how a great many organisations find out.

  • A customer, journalist or researcher tells you your data is being offered for sale.
  • Your organisation appears on an extortion leak site.
  • A supplier notifies you that their environment was breached.
  • Staff start receiving phishing that knows too much about internal detail.

Now the uncomfortable part. Sportadmin had monitoring and it stayed silent through the intrusion. Capita’s monitoring alarmed in 10 minutes and the compromised device stayed connected for 58 hours. Detection without a response path is not detection.

Decide today who is allowed to isolate a server at 02:00 on a Saturday without asking anyone first. Write the name down. As a cheap first look at exposure already in circulation, a domain breach checker will tell you whether credentials tied to your domain appear in known leaks.

How to Prevent a Data Breach

Data breach prevention is mostly a small number of controls applied without exceptions. Start with the technology.

  • Require multi-factor authentication on every service reachable from the internet, including remote access, VPN and legacy portals inherited through acquisitions.
  • Give every account the least access it needs and review privileges on a fixed schedule.
  • Patch internet-facing systems and web applications before anything else.
  • Encrypt personal data at rest and on anything portable.
  • Keep logs somewhere an attacker who owns the server cannot delete them.
How to Prevent a Data Breach

Then the process which is where the Swedish cases were decided.

  • Put someone on the alarm around the clock and give that person written authority to isolate a machine without convening a meeting.
  • Delete data you no longer need. Set retention periods for HR records, former employees and anything concerning children then enforce them in the supplier’s system as well as your own.
  • Ask every supplier what they hold about your people where it sits and how fast they will tell you if it leaks. Put the answer in the contract.
  • Write the incident plan with both reporting clocks in it and rehearse it once a year with the people who would actually be woken up.
  • Keep offline backups and test a restore at least once a year.

Finally the people who are involved in most breaches and are also the fastest detection system you have.

  • Train staff on phishing and on the ordinary breaches too, the misdirected email and the wrong attachment.
  • Make reporting a mistake fast and blameless because the cost of a breach is set by how quickly it is contained.
  • Run security awareness training as a routine rather than an annual slide deck.
  • Test the technical side with penetration testing before an attacker does.

None of this is advanced. Every failure in the four cases above was later described by a regulator as a basic control. Start with multi-factor authentication and with deleting data you no longer need. They cost the least and they take the most out of the blast radius.

Myths & Facts

Myth

Data breaches only happen to big companies.

If we were attacked, a fine cannot be our fault.

A data breach means hackers.

We have monitoring, so we would know.

A supplier's breach is the supplier's problem.

The 72-hour clock starts when we finish investigating.

Fact

IMY took 12,276 personal data breach notifications in 2025 from organisations of every size. The largest single driver was intrusions at suppliers serving many small customers, which puts the smallest organisations inside someone else's blast radius.

Regulators assess whether your security matched the risk. IMY imposed a SEK 6 million sanction fee on Sportadmin in January 2026 after finding known weaknesses left unaddressed and no real-time intrusion detection.

In the incident data the UK regulator publishes, more than three quarters of reported personal data breaches are non-cyber. The most common single cause is personal data emailed to the wrong recipient.

Sportadmin had monitoring that stayed silent through the intrusion. Capita's alarm fired in 10 minutes and the compromised device stayed connected for 58 hours. Monitoring counts only when someone can act on it.

The organisation that decided to place the data there is still the controller. After the Miljödata attack IMY opened investigations into three public-sector customers as well as the supplier itself.

It starts when you become aware of the breach. GDPR Article 33 lets you notify in phases and add detail later, so waiting for a complete picture is how organisations miss the deadline.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario simulation

  1. A supplier calls on a Friday afternoon. Their systems were breached and your employee records may be in the stolen data. They cannot yet say what was taken.

    What do you do first?

    • Wait for the supplier's full report before doing anything
    • Assess what data you placed with them and notify IMY within 72 hours if there is a risk
    • Email every employee straight away with what little you know
    • Ask the supplier to handle any notification on your behalf
  2. At 02:00 on a Saturday your monitoring raises a high-priority alert about unusual activity on a file server holding HR records.

    What is the right response?

    • Log it and review it on Monday morning
    • Isolate the server now under the standing authority in the incident plan, then investigate
    • Email the IT manager and wait for a reply
    • Reboot the server to clear whatever is running
  3. An employee emails a spreadsheet of staff sick-leave records to an external address by mistake and realises an hour later.

    How should this be handled?

    • It was human error, so it is not a data breach
    • Record it, assess the risk and notify IMY within 72 hours unless a risk is unlikely
    • Ask the recipient to delete it and close the matter
    • Report it only if the recipient opens the file
  4. A review finds your HR supplier still holds records for staff who left five years ago, including sick-leave notes.

    What is the strongest action?

    • Leave it, storage is cheap and the data may be useful
    • Set a retention period, enforce it and have the supplier delete everything past it
    • Encrypt the old records and keep them indefinitely
    • Copy the records to your own server for safekeeping

Knowledge test

  1. Under GDPR, how long do you have to notify the supervisory authority of a personal data breach?

    • 24 hours
    • 72 hours
    • One week
    • One month

    Article 33 sets 72 hours from becoming aware, unless the breach is unlikely to result in a risk.

  2. Which of these counts as a personal data breach under GDPR Article 4(12)?

    • Only unauthorised access by an external attacker
    • Any accidental or unlawful loss, alteration, disclosure or destruction of personal data
    • Only incidents that reach the media
    • Only incidents involving financial data

    The definition covers accidents as well as attacks. Destruction and alteration count too.

  3. What is the penalty ceiling for a security failure under GDPR Article 32?

    • €10 million or 2 percent of worldwide annual turnover
    • €20 million or 4 percent of worldwide annual turnover
    • There is no financial penalty
    • SEK 6 million

    Security failures sit in the lower tier of Article 83(4), capped at €10 million or 2 percent, whichever is higher.

  4. In the Capita case, how long passed between the high-priority alert and the compromised device being isolated?

    • 10 minutes
    • 58 hours
    • Two days
    • One week

    The alert fired within 10 minutes and containment took 58 hours, against an internal target of one hour.

  5. Under Cybersäkerhetslagen, when is the early warning for a significant incident due?

    • Within 24 hours
    • Within 72 hours
    • Within one month
    • Only after the final report

    The cascade runs 24 hours for the early warning, 72 hours for the incident report and one month for the final report.

  6. Which cause accounts for the largest share of personal data breaches reported to the UK regulator?

    • Ransomware
    • Nation-state attacks
    • Non-cyber causes such as email sent to the wrong recipient
    • Insider theft

    More than three quarters of reported breaches are classed as non-cyber, led by data emailed to the wrong recipient.

Take it with you

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most breaches begin with something a person did or missed. A reused password, a convincing phishing email, an attachment sent to the wrong address. None of that is solved by buying another tool.

Training is also a legal duty now. NIS2 Article 21.2g names security awareness training as a required measure. Cybersäkerhetslagen carried that into Swedish law on 15 January 2026. Article 20 puts the management body on the hook for approving and overseeing it.

eBuilder Security runs security awareness training for Swedish organisations alongside detection and response. The aim is plain. Fewer ways in. Staff who report a mistake in minutes instead of hiding it for a day.

Frequently Asked Questions

What is a data breach?

A data breach is a security failure that exposes information to people who should not have it. Under GDPR Article 4(12) that covers unauthorised access or disclosure and also accidental loss, alteration or destruction of personal data. A misdirected email counts. So does ransomware that destroys records.

What is a personal data breach under GDPR?

A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data or unauthorised access to it. The EDPB groups these into confidentiality, integrity and availability breaches. A single incident can fall into all three at the same time.

What are the main types of data breaches?

The main types are confidentiality breaches where data is exposed, integrity breaches where data is altered and availability breaches where data is lost or destroyed. By cause, the common routes are stolen credentials, phishing, supplier compromise, exposed systems, ransomware, insider misuse and everyday human error.

What is the average cost of a data breach?

There is no reliable single average. The global figure most often quoted comes from vendor-sponsored research on large organisations. Official UK statistics for 2025/2026 put the median perceived cost of the most disruptive breach at zero pounds, while regulators issued fines of SEK 6 million and £14 million in recent security cases.

How quickly must a data breach be reported in Sweden?

Under GDPR you must notify IMY within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to the people affected. If Cybersäkerhetslagen applies, a significant incident also needs an early warning within 24 hours, a report within 72 hours and a final report within one month.

Do we have to tell the people whose data was exposed?

Yes, where the breach is likely to result in a high risk to their rights and freedoms. GDPR Article 34 requires you to inform them without undue delay and in clear language, describing the likely consequences and the measures you are taking. Every breach must also be recorded internally, including unreported ones.

Can we be fined even though we were the victim of an attack?

Yes. Regulators assess whether your security was appropriate to the risk you were carrying. IMY set a SEK 6 million sanction fee against Sportadmin in January 2026 after finding no real-time intrusion detection and excessive account privileges. Being the target of a crime does not excuse an Article 32 failure.

How do we know if we have had a data breach?

Often you will not know from the inside. Watch for logins from unusual locations, unexplained data transfers, new privileged accounts and logging being switched off. Many organisations learn from outside, when data appears for sale or a supplier calls. Check whether credentials tied to your domain already appear in known leaks.

How do you prevent a data breach?

Start with multi-factor authentication on everything reachable from the internet, least-privilege access and deletion of data you no longer need. Add real-time monitoring with someone authorised to act on an alert, tested offline backups, supplier contracts that require prompt breach notification and regular staff training.

Get a 30-Minute Security Briefing. No Pitch Deck.

Talk to a Sweden-based analyst. We'll review your posture, map your NIS2 gaps, and give you a clear picture of where you stand, in plain language.

Book a Free Briefing
No commitment Sweden-based analyst

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.