Volvo Group Reports Data Breach Following Ransomware Attack on HR Vendor
On Sun, Aug 20, 2025, Miljödata, a provider of HR management services to Volvo Group, experienced a ransomware attack, resulting in the encryption of systems and operational disruption. The attack was identified on Wed, Aug 23, 2025, by the cybersecurity…
On Sun, Aug 20, 2025, Miljödata, a provider of HR management services to Volvo Group, experienced a ransomware attack, resulting in the encryption of systems and operational disruption. The attack was identified on Wed, Aug 23, 2025, by the cybersecurity team upon noticing suspicious activity within the network.
Further investigation revealed on Sat, Sep 2, 2025, that employee data may have been compromised. Miljödata promptly informed Volvo Group and initiated containment measures. The breach was limited to the vendor's environment, leaving Volvo Group's IT infrastructure unaffected.
The breach potentially exposed basic personal identifiers such as first and last names and Social Security numbers. There is no evidence of access to payroll, bank account details, or insurance information. The exposure of Social Security numbers represents a heightened risk of identity theft and fraud.
Volvo Group is collaborating with Miljödata to assess the full scope of the data exposure. Miljödata has engaged external cybersecurity experts for a comprehensive forensic investigation and to enhance the security of its systems. Concurrently, Volvo Group is evaluating its vendor management and data protection policies.
The attack was identified on Wed, Aug 23, 2025, by the cybersecurity team upon noticing suspicious activity within the network.
As a mitigation measure, Volvo Group is offering affected employees a complimentary 18-month subscription to Allstate’s Identity Protection Pro+ service, which includes:
Tri-bureau credit monitoring Monthly credit score tracking Dark-web monitoring Full-service identity restoration assistance
Detailed enrollment instructions will be sent via email and postal mail to the impacted employees. Employees are advised to monitor bank and credit card statements for any irregularities. Additionally, they can obtain free annual credit reports from the major credit bureaus and implement fraud alerts or security freezes.
Volvo Group’s People Services team remains available to assist employees with identity protection measures. This incident underscores the importance of rigorous vendor security oversight to safeguard against third-party cyber threats.
Based on reporting by GBHackers.
