Sweden — Cyber Threat Profile
Sweden faces persistent Russian hybrid operations, categorically elevated since its NATO accession in March 2024. In January 2024, the Russian-linked Akira ransomware group attacked IT provider Tietoevry, disrupting operations across 120 government agencies and forcing a multi-week recovery. From November 2024, the National Cybersecurity Centre was formally consolidated under the Defence Radio Establishment (FRA), expanding its mandate for private sector coordination and threat analysis. Sweden was the Nordic country most cited in 2024 dark web monitoring, with finance and insurance sectors most targeted.- National CERT/CSIRT: CERT-SE
- Data protection authority: Integritetsskyddsmyndigheten (IMY) (source: CNIL)
- World Cybercrime Index 2024 (origin significance): 0.21 / 100, #71 worldwide
- Secure Internet servers per 1M people (2024): 55,097.3 (source: World Bank)
- Internet users (2025): 95.8% of population (source: World Bank)
Threat actors targeting Sweden
- Anonymous Sudan Hacktivist
- APT28 APT
- NoName057(16) Hacktivist
- ZIRCONIUM APT
- Qilin Ransomware · 12 incident(s)
- Akira Ransomware · 10 incident(s)
- Play Ransomware Ransomware · 10 incident(s)
- 8Base Ransomware · 7 incident(s)
- The Gentlemen Ransomware · 7 incident(s)
- RansomHub Ransomware · 6 incident(s)
- DragonForce Ransomware · 5 incident(s)
- INC Ransom Ransomware · 5 incident(s)
- Lynx Ransomware Ransomware · 5 incident(s)
- Deadlock Ransomware · 3 incident(s)
- Fog Ransomware Ransomware · 3 incident(s)
- LockBit Ransomware · 3 incident(s)
- Black Basta Ransomware · 2 incident(s)
- Cl0p Ransomware · 2 incident(s)
- RansomHouse Ransomware · 2 incident(s)
- Sarcoma Ransomware · 2 incident(s)
- World Leaks Ransomware · 2 incident(s)
- BianLian Ransomware · 1 incident(s)
- BlackByte Ransomware · 1 incident(s)
- Cactus Ransomware · 1 incident(s)
- Coinbase Cartel Ransomware · 1 incident(s)
- Dire Wolf Ransomware · 1 incident(s)
- Exfil Squad Ransomware · 1 incident(s)
- FunkSec Ransomware · 1 incident(s)
- Hunters International Ransomware · 1 incident(s)
- Lamashtu Ransomware · 1 incident(s)
- LAPSUS$ Hacktivist · 1 incident(s)
- Medusa Ransomware Ransomware · 1 incident(s)
- Meow Ransomware · 1 incident(s)
- NightSpire Ransomware · 1 incident(s)
- Rhysida Ransomware · 1 incident(s)
- SafePay Ransomware · 1 incident(s)
- ShinyHunters Ransomware · 1 incident(s)
- Killnet Hacktivist
Most targeted sectors
- Manufacturing 27 incident(s)
- Business & Professional Services 11 incident(s)
- Government & Public Sector 7 incident(s)
- Technology 7 incident(s)
- Hospitality & Tourism 6 incident(s)
- Transportation & Logistics 5 incident(s)
- Healthcare 4 incident(s)
- Retail & Consumer 4 incident(s)
- Education & Research 2 incident(s)
- Telecommunications 2 incident(s)
- Agriculture & Food 1 incident(s)
- Construction 1 incident(s)
Recent claimed incidents
- Wishfully Studios 2026-08-17 · Technology
- Depona 2026-08-07 · Technology
- Axson Teknik 2026-08-07 · Manufacturing
- Krafman 2026-07-31 · Manufacturing
- Bonava 2026-07-26 · Manufacturing
- Carrier AB 2026-07-25 · Manufacturing
- Byggelit Sverige 2026-07-16 · Construction
- Svensk Direktreklam 2026-07-16 · Business Services
- Tooltec 2026-07-16 · Manufacturing
- ONE Contact 2026-07-10 · Business Services
- Hornavan Hotell 2026-06-15 · Hospitality and Tourism
- INGKA GROUP 2026-06-13 · Consumer Services
- Areco 2026-06-11
- GDL Transport 2026-06-09 · Transportation/Logistics
- GDL Transport 2026-06-09 · Transportation/Logistics