According to the company, 2.2 million people were affected by the cyberattack last fall.
IMY's review shows that the company did not have a sufficiently high level of technical and organisational security.
They have not carried out sufficient checks when installing new software and have not had automatic real-time monitoring of their systems to detect intrusions and suspicious activity, IMY writes in a press release.
"Here, Environmental Data has failed and the result is that a threat actor came across information about a large part of Sweden's population. We take what happened seriously," says IMY Director General Eric Leijonram in a comment.





