FB pixel

Sweden’s BankID breached by hacker group as gov’t prepares e-ID launch

Sweden’s BankID breached by hacker group as gov’t prepares e-ID launch
 

Hackers have claimed they’re behind a breach linked to Sweden’s digital identity system, leaking code and credentials that could reveal how citizens authenticate into government services. It comes as Sweden gears up to launch a government e-ID in December.

The hacker group calls itself ByteToBreach and claims to have stolen a large dataset from CGI’s Swedish division, including source code reportedly used by public authorities.

Other databases containing personal data and electronic signature documents are allegedly being sold separately. One affected system is said to support BankID logins for the Swedish Tax Agency.

In a demonstration of the threats facing national digital public infrastructure, the incident throws an unfortunate spotlight on Sweden’s digital identity system. BankID is Sweden’s primary electronic ID, used daily by millions to access government portals, banks, payments and digital signatures.

The Swedish government is planning to launch Sverige-ID on December 1, 2026, giving both citizens and foreign residents an official alternative to the popular BankID, which was developed by Swedish banks as a digital identity service. The Sverige-ID will allow users to identify themselves, share information and provide e-signatures. The e-ID will also allow access to other EU countries’ digital services.

The hackers’ data dump appeared on the cybercrime forum Breached on Thursday night and was first reported by major Swedish newspapers Aftonbladet and Dagens Nyheter, reports Cybernews. Journalists at Dagens Nyheter reviewed parts of the leaked material, which they say include source code, passwords, and encryption keys. Cybernews could not independently verify the files, as the Breached forum was taken offline over the weekend by a cybersecurity initiative.

The Swedish Tax Agency sought to allay fears, saying there is no sign of direct impact. “We take all incidents seriously, but we don’t see anything that affects us right now,” said Peder Sjölander, the agency’s IT Director.

CGI later confirmed the breach. The company said attackers accessed a “limited number” of  internal test servers in Sweden. These servers were linked to a service used by a “limited number” of customers. CGI added that the intruders obtained an older version of the application’s source code and claims that production environments or operational data were not affected.

The breach nonetheless highlights the growing pressure on digital identity systems. BankID itself has been targeted before. Last year, a major DDoS attack knocked the service offline for hours, leaving more than 8.6 million users unable to log in to banks or send or receive money. Sweden’s population numbers just over 10 million.

The country has also faced a string of high‑profile cyber incidents. A Cybernews investigation uncovered a massive leak exposing over 100 million private records of Swedish citizens. IT supplier Miljödata suffered a ransomware attack that hit around 200 municipalities and regions, with personal data from 1.5 million people reportedly stolen. And Svenska kraftnät, the national electricity grid operator, confirmed a breach after the Russia‑linked Everest ransomware gang claimed to have siphoned hundreds of gigabytes of data.

With Sweden expanding digital public infrastructure and digital authentication for public and financial services, the resilience of its digital ID ecosystem is closely connected to national security as conversations around digital sovereignty also increase in urgency.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events