Sweden — Cyber Threat Profile

Sweden is consolidating its cybersecurity architecture under the National Cybersecurity Strategy 2025-2029: by 1 July 2026 the signals-intelligence agency FRA absorbs the operational cyber duties long held by the civil-contingencies agency MSB, and a new Cybersecurity Act (2025:1506) transposing the EU's NIS2 directive took effect 15 January 2026. Ransomware remains the dominant threat: in late August 2025 an attack on IT supplier Miljodata paralysed HR systems at roughly 200 of Sweden's 290 municipalities and some of its 21 regions, exposing sick-leave and medical-certificate data. Sweden continues to report elevated Russian-linked hybrid activity since its NATO accession on 7 March 2024.

Threat actors targeting Sweden

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions