Sweden

Country

Databreach at Swedish Power Grid Operator Svenska kraftnät

October 25, 2025

Swedish Electricity Provider (Svenska kraftnät) confirmed it suffered a data breach. The incident, disclosed on October 26, 2025, is linked to the notorious Everest ransomware gang. The organization maintains that Sweden’s power infrastructure continues to operate normally, with no disruptions to electricity transmission or distribution across the country. The Everest group alleged that it had stolen 280 GB of data from a file transfer solution.

read more

DDoS Attack Compromised Systems at Popular FlightRadar24.

March 4, 2025

Flightradar24, a popular flight tracking service, was affected by a cyber incident that compromised their systems. The incident may have exposed email addresses and password hashes of some users. The attack prompted the company to reset passwords and instruct affected users to change them. No personal or payment information was compromised, and the company has taken steps to contain the incident.

read more

Aircraft Unable to Receive GPS Signals in Baltic Sea, the Black Sea and Eastern Mediterranean.

March 22, 2024

Russia is suspected of launching a record-breaking 63-hour-long attack on GPS signals. The Baltic Sea, the Black Sea and the eastern Mediterranean – the regions where Russia’s military has been most active – have seen an increase in disruption to the Global Positioning System (GPS). This has left aircraft unable to receive GPS signals.

The incident, which affected hundreds of passenger jets, occurred amid rising tensions between Russia and the NATO military alliance more than two years since the start of Russia’s full-scale invasion of Ukraine.

read more

Cyberattack on Ball Bearings Manufacturer SKF in Sweden

February 19, 2024

SKF Mekan was targeted in a cyberattack that disrupted its IT systems. The attack, which was reportedly stopped by the company’s security team, had an impact on the company’s operations. The incident is believed to have been a ransomware attack, with the attackers seeking financial gain.

read more

Customers affected after Cyberattack at Swedish IT Company

February 6, 2024

IT provider Advania was hit by a cyber attack on Tuesday attack.
Around 60 of the company’s customers are affected, of which between 10 and 15 are healthcare centres. “We cannot read any medical records or take any samples and can only write paper prescriptions. We cannot receive any patients,” says Per Svensson, director of operations at Herkules care center in Borås, to Borås Tidning. Some health centers have closed completely on Wednesday, while others receive patients on drop-in and write with paper and pencil because they do not have access to the medical record system.

There is no indication that ransomware has been introduced into the system. There is currently no forecast for when the problem may be fixed.

read more

Production Shut Down at Swedish Dairy

April 16, 2024

During Tuesday, Norrmjerier discovered that the dairy in Umeå had been exposed to a cyber attack. All production in Umeå is down and a crisis management team has been activated.

By Tuesday afternoon, Norrmejerier announced the resumption of food fat production at the Umeå dairy following the cyberattack. However, other operations remained suspended as efforts to investigate the cyberattack were underway.

Despite the disruption, milk collection has been ongoing, with transportation to Norrmejerier’s daries in Burträsk and Luleå, which are unaffected by the attack. Additionally, Arla and Falköping dairy have extended assistance to Norrmejerier.

read more

Numerous Customers Suffer from Ransomware Attack at Cloud Provider Tietoevry

January 20, 2024

Cloud hosting services provider Tietoevry announced that one of its datacenters in Sweden “was partially subject to a ransomware attack” this weekend, affecting numerous customers and forcing stores to close across the country.

According to the Finland-based technology company’s statement on Monday, the attackers used the Akira ransomware-as-a-service tools. The incident was limited to “one part of one of our Swedish datacenters” and is believed to have only impacted services to some of Tietoevry’s customers in Sweden. However, these customers include Primula, a widely used payroll and HR company in Sweden, including by the majority of the country’s universities and more than 30 government authorities. Staff at these organizations cannot submit personal leave or expenses requests.

Primula customers include the Swedish State Service Centre (SSC), which itself manages administrative services including payroll for nearly 170 government agencies. Swedish businesses currently reporting issues due to the incident include cinema chain Filmstaden and retailer Rusta. As a result of the ransomware attack, Granngården announced its grocery stores across the country would be closed on Monday.

On April 24, the company reports: With the exception of efforts continuing with few customers, all other impacted customer services were fully restored by mid-March.

read more

Ransomware Attack on Skanlog Triggered Nationwide Alcohol Shortage

April 22, 2024

Systembolaget’s wine and spirit distribution in Sweden was disrupted after Skanlog, a logistics company was the victim of a ransomware attack. The incident has disrupted supplies. Skanlog has not suggested when operations might return to normal. Systembolaget’s spokesperson said the company had a backup plan if its distributor was unable to resume deliveries. “It affects about a quarter of our sales volume.” says Teodor Almqvist, press officer at Systembolaget.

The logistics company Skanlog told Swedish media that it first identified a ransomware attack by hackers based in North Korea on Monday morning (April 22). It was not clear how they determined a possible source, and Skanlog did not immediately respond to a request for comment.

read more

Cyber Incident at Software co. Formpipe’s Danish Subsidiary

October 17, 2024

Formpipe has reported a computer security incident within its Danish subsidiary. The incident resulted in a data security breach, but details on the extent and consequences of the incident are not yet available. The investigation is ongoing to determine the causes and implications of the incident.

read more