Sportadmin Fined 6 Million Kronor for Massive Data Breach Affecting 2.1 Million

The Swedish Data Protection Authority fines Sportadmin 6 million kronor following a major 2022 data breach exposing sensitive data of over 2 million individuals, including children and royalty.

    Key details

  • • Sportadmin fined 6 million kronor by the Swedish Data Protection Authority (IMY).
  • • Data breach exposed personal information of 2.1 million individuals, including children and high-profile figures.
  • • Investigation revealed serious technical and organizational security flaws and prior awareness of vulnerabilities at Sportadmin.
  • • Breach involved ransomware attack by Ransomhub exploiting outdated systems and a 2022 technical error.
  • • IMY highlights importance of adequate security despite the inevitability of cyberattacks.

The Swedish Data Protection Authority (Integritetsskyddsmyndigheten, IMY) has fined Sportadmin 6 million kronor due to a substantial data breach that compromised personal information of over 2.1 million individuals. This breach, revealed following an investigation launched after the 2022 incident, exposed names, contact details, personal identification numbers, and sensitive health information, including data of children, young people, and high-profile figures such as Prince Carl Philip, whose secret online alias was also leaked.

IMY's probe uncovered significant technical and organizational shortcomings at Sportadmin, with the company reportedly aware of vulnerabilities before the breach. The attack, orchestrated by the ransomware group Ransomhub, exploited outdated systems and a technical error from 2022, using a known hacking method linked to web forms. Though the attack aimed to extort money by threatening to leak data on the darknet, Sportadmin denies having paid any ransom.

IMY Director Eric Leijonram emphasized that while IT attacks can't be entirely prevented, organizations must uphold security standards appropriate to the sensitivity of the data they manage. The breach's impact, involving protected individuals and members of the royal family, underscores the critical need for robust cybersecurity measures.

This fine marks a significant enforcement of GDPR compliance in Sweden, spotlighting the consequences of inadequate data protection.

This article was translated and synthesized from Swedish sources, providing English-speaking readers with local perspectives.

Source comparison

The key details of this story are consistent across the source articles

The top news stories in Sweden

Delivered straight to your inbox each morning.