LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 5.4M Swedes' Data Allegedly Leaked on Hacker Forums

HIGH severityReportedHow we verify

5.4M Swedes' Data Allegedly Leaked on Hacker Forums: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 16, 2026
5.4M Swedes' Data Allegedly Leaked on Hacker Forums

Reported June 16, 2026. Approximately 5.4M people affected.

HIGH
Severity
5.4M
People affected
5
Data types exposed
June 16, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A data breach involving ilait.se was reported on June 16, 2026, exposing names, addresses, phone numbers, location data, and property data of 5.4 million Swedes on hacker forums. Individuals are advised to check if their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityReported
Contact / identity PII exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
5.4M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On June 16, 2026, reports indicated that a dataset said to contain personal information on 5.4 million Swedish citizens had been advertised on hacker forums, with claims that it originated from ilait.se and adressfakta.se. The incident sits within a broader pattern of large personal-data listings appearing on underground platforms, where questions of sourcing and verification frequently arise. The scale of the claim and the population coverage involved make the matter relevant to data-handling practices in Sweden.

Inside the incident

A threat actor advertised a dataset containing personal information on over 5.4 million Swedish citizens, claiming it came from a corporate breach of data distributors ilait.se and adressfakta.se. The records reportedly include names, addresses, phone numbers, and some property or tax details. No information has been provided on when any access occurred, how it was obtained, or the exact volume of records involved. Researchers note much of the data appears publicly available under Sweden's transparency rules and question whether it stems from a genuine hack or data broker compilation.

How a breach like this happens

Incidents of this type often begin when an actor obtains unauthorized access to systems that store or distribute collected records. Access may result from compromised credentials, misconfigured services, or other entry points into corporate infrastructure. Once material is removed, it can be packaged and offered on forums. In sectors that manage address and property information, the boundary between openly accessible public records and internal datasets can complicate later assessments of what constitutes a breach.

ilait.se and its sector

ilait.se functions as a data distributor in Sweden, a sector that aggregates and supplies address, property, and related records to commercial and public users. Organizations of this kind routinely process information on large segments of the population. An incident involving such an entity draws attention because the data types involved are already subject to public-access rules in Sweden, raising separate questions about how additional or compiled records are secured.

What was likely exposed

The reported dataset is claimed to contain the following categories of information:

Exact contents remain unconfirmed. Researchers have observed that substantial portions of the material appear consistent with publicly available Swedish records, leaving open the possibility that the advertised set is a compilation rather than the direct result of unauthorized system access.

The real-world impact

Individuals whose details appear in such a listing may experience an increase in unsolicited communications or attempts to combine the information with other sources. Organizations face potential regulatory review and questions about data-handling controls. Because much of the material may already be obtainable through public channels, the incremental risk depends on whether any non-public elements were included and how the dataset is subsequently used or shared.

Were you affected?

People who wish to check their status can review any notifications issued by ilait.se or relevant authorities. Running a free exposure scan of an email address against known breach data provides one practical way to determine whether the address has appeared in previously reported incidents. Monitoring credit files and limiting unnecessary sharing of personal details remain standard precautions in the meantime.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

Companyilait.se security record
74/100
DoxxScan™ · Moderate doxx risk
C 68Mixed record

1 reported incident on record.

See ilait.se’s full breach history →

More recent breaches

Aflac Japan Discloses Breach Impacting 4.38M CustomersJune 30, 2026Moody Bible Institute Data Breach (2026)June 15, 2026ShinyHunters Claims 297GB HR and Payroll Data from Council of EuropeJune 14, 2026Now-Forward Non-Profit Breached by CMD GroupMay 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 5.4M Swedes' Data Allegedly Leaked on Hacker Forums →

Source: Cybernews

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram