Drooid Logo
Back to story perspectives

Full Breakdown

Data Breaches Raise Concerns Over Data Protection in Sweden and the U.S.

11/7/2025, 8:16:16 AM

Overview of Recent Data Breaches

Recent data breaches in Sweden and the United States have highlighted significant vulnerabilities in data protection practices across various sectors. Notably, incidents involving Swedish IT firm Miljödata, automotive technology provider Hyundai AutoEver America, and business process outsourcing firm Conduent have raised alarms regarding the handling of sensitive personal information.

Miljödata Data Breach Investigation

In late August 2023, Miljödata experienced a serious data breach that compromised the personal information of over 1.5 million individuals. The Swedish Data Protection Authority (IMY) has initiated a major investigation into the incident, which involved the theft and publication of sensitive data on the Darknet. The investigation will assess compliance with General Data Protection Regulation (GDPR) requirements among Miljödata and several public sector organizations, including the City of Gothenburg and Älmhult Municipality. IMY's head of unit, Jenny Bård, emphasized the need to examine the company’s security measures and the types of personal information stored, aiming to uncover shortcomings in data protection practices.

Hyundai AutoEver America Breach Details

Hyundai AutoEver America disclosed a significant data breach on March 1, 2025, after unauthorized activity was detected within its IT environment. The breach, which began on February 22, 2025, exposed sensitive personal information, including Social Security numbers and driver’s license details. The company engaged external cybersecurity experts to investigate the breach, which lasted approximately nine days. Hyundai AutoEver is offering affected customers complimentary two-year credit monitoring services and has advised them to remain vigilant against potential identity theft.

Conduent's Large-Scale Data Breach

Conduent confirmed a large-scale data breach that may have affected over 10 million individuals, with the intrusion detected in January 2025 after several state agencies reported system disruptions. The breach, attributed to a ransomware gang known as SafePay, involved the theft of sensitive data, including names, Social Security numbers, and medical records. Conduent has incurred significant costs in response to the breach and is facing potential legal and reputational repercussions.

South Gloucestershire Council's Data Publication Error

In a separate incident, South Gloucestershire Council mistakenly published sensitive personal data of 625 individuals who participated in a consultation regarding the Local Plan. The council reported the breach to the Information Commissioner’s Office (ICO) and has taken immediate steps to rectify the situation. The data, which included names and contact details, was accessible online for approximately three days due to an error in the publication process.

Official Responses and Future Implications

Authorities in both Sweden and the U.S. are taking steps to address these breaches and improve data protection measures. The IMY's investigation into Miljödata and the actions taken by Hyundai AutoEver and Conduent reflect a broader commitment to accountability in the wake of data breaches. As these incidents unfold, they underscore the pressing need for robust cybersecurity practices and responsible data management across all sectors.

Verbatim Quotes

  • “Jenny Bård, head of unit at IMY, stated that this leak exposed sensitive information for a vast number of individuals.” — Jenny Bård, Head of Unit, IMY
  • “We have written to notify all of the potentially affected individuals and organisations to apologise, and have referred the matter to the Information Commissioner’s Office.” — South Gloucestershire Council Spokesperson
  • “Related content A spokesperson for the council said: “We can confirm that a data breach occurred in relation to the publication of the council’s new Local Plan last month.” — Patrick Conroy, Planning Policy Manager, South Gloucestershire

Conflicting Reports & Gaps

While the Miljödata breach has been confirmed to affect over 1.5 million individuals, the exact number of individuals impacted by the Hyundai AutoEver and Conduent breaches remains unspecified. Additionally, the full scope of data compromised in each incident is still under investigation, leaving potential gaps in understanding the complete impact on affected individuals.