Ransomware
⛓ Supply Chain
TietoEVRY Ransomware Attack (Swedish Universities, Municipalities, Companies)
Primary Source ↗Incident Details
On January 19-20, 2024, TietoEVRY, a Finnish-Norwegian IT company and one of the largest IT service providers in the Nordics, suffered an Akira ransomware attack against its Sweden-based cloud hosting infrastructure. The attack disrupted services for dozens of Swedish customers across government, education, retail, and private sectors. Confirmed affected organizations include Uppsala County Council, Vellinge Municipality, Statens Service Center, Malmö University, Lund University, Stockholm University, University West, SLU (Swedish University of Agricultural Sciences), Karolinska Institutet, Grangnården, Moelven, Rusta, and Filmstaden. TietoEVRY worked to restore systems but many customers experienced multi-day to multi-week service outages affecting business-critical systems. This was one of the most impactful Nordic IT supply chain ransomware events of 2024.
Technical Details
- Initial Attack Vector
- Akira ransomware group deployed ransomware against TietoEVRY's Sweden-based cloud hosting platform, impacting one of TietoEVRY's datacenters and disrupting cloud services for dozens of Swedish customers
- Vendor / Product
- TietoEVRY (cloud hosting and IT services)
- Malware Family
- Akira ransomware
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-01-19 Breach occurred
- 2024-01-20 Publicly disclosed
- 2024-01-20 Customers notified