Sportadmin Fined 6 Million Kronor for Massive Data Breach Affecting 2.1 Million
The Swedish Data Protection Authority fines Sportadmin 6 million kronor following a major 2022 data breach exposing sensitive data of over 2 million individuals, including children and royalty.
- • Sportadmin fined 6 million kronor by the Swedish Data Protection Authority (IMY).
- • Data breach exposed personal information of 2.1 million individuals, including children and high-profile figures.
- • Investigation revealed serious technical and organizational security flaws and prior awareness of vulnerabilities at Sportadmin.
- • Breach involved ransomware attack by Ransomhub exploiting outdated systems and a 2022 technical error.
- • IMY highlights importance of adequate security despite the inevitability of cyberattacks.
Key details
The Swedish Data Protection Authority (Integritetsskyddsmyndigheten, IMY) has fined Sportadmin 6 million kronor due to a substantial data breach that compromised personal information of over 2.1 million individuals. This breach, revealed following an investigation launched after the 2022 incident, exposed names, contact details, personal identification numbers, and sensitive health information, including data of children, young people, and high-profile figures such as Prince Carl Philip, whose secret online alias was also leaked.
IMY's probe uncovered significant technical and organizational shortcomings at Sportadmin, with the company reportedly aware of vulnerabilities before the breach. The attack, orchestrated by the ransomware group Ransomhub, exploited outdated systems and a technical error from 2022, using a known hacking method linked to web forms. Though the attack aimed to extort money by threatening to leak data on the darknet, Sportadmin denies having paid any ransom.
IMY Director Eric Leijonram emphasized that while IT attacks can't be entirely prevented, organizations must uphold security standards appropriate to the sensitivity of the data they manage. The breach's impact, involving protected individuals and members of the royal family, underscores the critical need for robust cybersecurity measures.
This fine marks a significant enforcement of GDPR compliance in Sweden, spotlighting the consequences of inadequate data protection.
This article was translated and synthesized from Swedish sources, providing English-speaking readers with local perspectives.
Source articles (2)
Mångmiljonböter för Sportadmin-läcka
Miljonböter för läckan från Sportadmin
Source comparison
Latest news
Midsummer 2026 Marked by Violence, Disturbances, and Rare Outdoor Rape in Sweden
Dutch Team Faces Injury Woes and Apprehension Ahead of 2026 World Cup Clash with Sweden
Sweden Eyes Strong World Cup Run After Thrashing Tunisia, Faces Tough Battle Against Netherlands
Professor Francis J. Gavin Advocates Historical Insight to Enhance Political Decision-Making
Sweden Tightens Parental Benefit Fraud Sanctions Amid Debate on Political Morality and Politician's Conviction for Threats
Swedish Economy Set for Strong Recovery in Late 2026 Amid Steady Riksbank Interest Rates
The top news stories in Sweden
Delivered straight to your inbox each morning.