A Swedish software supplier told its regulator why it never checked the version of a firewall component it had just installed. It was an expensive product from a well-known supplier.
The regulator was not persuaded. On 22 September, Sweden’s data protection authority IMY fined Miljödata SEK 1.8 million, and its reasoning is a lesson in supplier security for every firm that hosts other organisations’ data.
What IMY found
Miljödata supplies web-based HR and work-environment systems, handling sick leave, rehabilitation and workplace incidents for more than 300 customers. According to IMY’s decision, the people in its systems were mainly its customers’ employees. IMY’s announcement adds that those customers include municipalities across Sweden, several regions and state agencies.
In August 2025, an attacker used an SQL injection against a support component of a firewall solution. Miljödata had installed that component about a week earlier. The version it received was outdated and carried a critical vulnerability, and the supplier had published information about that vulnerability more than a year before the installation.
From there, the attacker escalated privileges and moved between servers for three days before any alarm went off. The company puts the number of people affected at around 2.2 million, and part of the stolen data was later published on the dark web.
IMY found a breach of Article 32(1) GDPR, which requires security appropriate to the risk. It also judged the company negligent.
Two basic measures IMY found wanting
IMY called two measures basic, and Miljödata fell short on both.
The first was a version check, which is supplier security in its plainest form. The component went onto an internet-facing server without passing through a test environment, which, in IMY’s view, made it especially important to confirm that the right version had arrived. Miljödata had an approval process for new components. It simply saw no reason to check this one, because of the price and the name on the box.
The second was security monitoring. Miljödata did have monitoring, but IMY found it was aimed mainly at performance and availability. The attacker bypassed virus detection and multi-factor authentication, and nothing flagged the intrusion until services began to fail. After the incident, the company introduced round-the-clock EDR and SOC monitoring.
Monitoring that watched the wrong thing
That second point deserves a moment. A dashboard showing that systems are up is not the same as a control showing that nobody is inside them. For supplier security, it is the second kind that counts.
IMY counted the speed of the fix against the company. Miljödata was able to introduce real-time monitoring shortly after the incident, which showed the measure had been within reach all along.
Why supplier security lands on B2B service firms
The decision records that Miljödata acted mainly as a processor for its customers. IMY did not need to settle the role question, because Article 32 binds controllers and processors alike.
That matters for any B2B services firm that hosts, analyses or processes data for its clients. In that relationship, your firm is the supplier. Your clients’ supplier security depends on the checks you run on your own suppliers, including the components nobody thinks about once the invoice is paid.
The low-profile assumption
One line in the decision should make risk owners uncomfortable. Miljödata’s risk assessment rated the likelihood of a cyberattack as relatively low, partly because of the company’s limited public profile.
The attack did not care about profile. It exploited a known vulnerability in an exposed component, an attack that does not depend on who the target is. Supplier security that leans on obscurity is a bet, not a control.
Arguing that it was minor
Miljödata also argued that, if anything, a reprimand would suffice. IMY rejected that, finding the infringement was not minor and rating its seriousness as high.
The day before, the EDPB announced draft guidelines that draw the same line: a minor infringement generally attracts a reprimand, and anything else carries a strong presumption of a fine. Miljödata is an early illustration of how hard the “minor” argument is to win once sensitive data on millions of people has leaked, and of how a supplier security failure becomes a governance finding.
What supplier security asks of the people who approve components
None of this is specific to firewalls. The same reasoning applies to any component, plug-in or model that enters an environment holding personal data, and AI tooling is no exception. A tool from a famous vendor is still a tool whose version, configuration and reach someone has to confirm, as Monday’s piece on AI sandboxes argued from a different angle.
Three questions follow directly from the decision. Who in your organisation confirms that what arrived is what was ordered, and against which source? Does your monitoring tell you when systems are slow, or when someone is inside them? And does your risk assessment rest on an assumption, such as a low profile, that an attacker would not share?
Vendor reputation still has its uses in supplier security. It tells you who is worth buying from, and it belongs in how you govern a vendor relationship. It cannot replace the check itself, and the obligations that follow from a supplier’s failure can stay with you, as the AI Act’s value-chain rules show in a different context.
Miljödata can still appeal. Whatever happens in court, the regulator’s reasoning is already public, and it treats supplier security as something an organisation does, not something it buys.
Future Prep tracks enforcement decisions like this one for what they mean in practice for EU-operating organisations. The analysis continues on the FP website.