Enforcement
EN Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security
€565,000 fine - Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
Content
The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category data of 2,126,075 individuals, including minors, beeing published in the darknet. The attack happend due to an succesfull SQL injection on one of the controllers websites, which had not been protected against this kind of attack, granting the attacker access to the controllers server, allowing him to exfiltrate said data.
GDPR Articles: Art. 32 (1) GDPR
Industry: Industry and Commerce