Sportadmin gets SKr 6m fine for lacking IT security

Personal data of a large part of Sweden’s population was leaked on the darknet following an attack on the company in January 2025.

Sportadmin has been fined SKr 6m ($670,786) by IMY (the Swedish Data Protection Authority) following an IT attack in January 2025 that led to a large amount of personal data being leaked.

In the attack, the hacker obtained information about more than 2.1 million people – which was subsequently published on the darknet.

The

Register for free to keep reading

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day