Ransomware ⛓ Supply Chain

TietoEVRY Ransomware Attack (Swedish Universities, Municipalities, Companies)

📅 2024-01-19 🏢 TietoEVRY (cloud hosting and IT services) 🦠 Akira ransomware
Primary Source ↗

Incident Details

On January 19-20, 2024, TietoEVRY, a Finnish-Norwegian IT company and one of the largest IT service providers in the Nordics, suffered an Akira ransomware attack against its Sweden-based cloud hosting infrastructure. The attack disrupted services for dozens of Swedish customers across government, education, retail, and private sectors. Confirmed affected organizations include Uppsala County Council, Vellinge Municipality, Statens Service Center, Malmö University, Lund University, Stockholm University, University West, SLU (Swedish University of Agricultural Sciences), Karolinska Institutet, Grangnården, Moelven, Rusta, and Filmstaden. TietoEVRY worked to restore systems but many customers experienced multi-day to multi-week service outages affecting business-critical systems. This was one of the most impactful Nordic IT supply chain ransomware events of 2024.

Technical Details

Initial Attack Vector
Akira ransomware group deployed ransomware against TietoEVRY's Sweden-based cloud hosting platform, impacting one of TietoEVRY's datacenters and disrupting cloud services for dozens of Swedish customers
Vendor / Product
TietoEVRY (cloud hosting and IT services)
Malware Family
Akira ransomware
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-01-19 Breach occurred
  2. 2024-01-20 Publicly disclosed
  3. 2024-01-20 Customers notified