LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Swedish Arts Council Listed by ransomhouse Ransomware Group

HIGH severityUnverified claimHow we verify

Swedish Arts Council Listed by ransomhouse Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 31, 2025
Swedish Arts Council Listed by ransomhouse Ransomware Group

Reported October 31, 2025.

HIGH
Severity
October 31, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Swedish Arts Council was listed by the ransomhouse ransomware group on October 31, 2025, after internal files were exfiltrated in a ransomware attack. Individuals whose data may have been involved should check the organisation’s official notices and follow any guidance provided.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target public-sector bodies across Europe, treating government agencies as high-value victims whose operational disruption and data exposure can generate pressure for payment. Against that backdrop, the Swedish Arts Council, known in Swedish as Kulturrådet, was listed by the ransomhouse ransomware group on 31 October 2025. Public reporting states that internal files were exfiltrated in a ransomware attack; the number of people affected remains unknown, and further technical details have not been disclosed.

The listing itself is a claim by the group rather than an independently verified confirmation of every asserted detail. For an agency that distributes public cultural funding and holds records connected to artists, organisations and grant processes, any confirmed compromise of internal material carries practical consequences for both the institution and the individuals whose information may be involved.

Breaking down the breach

According to the available record, the Swedish Arts Council was listed by ransomhouse on 31 October 2025. The reported summary characterises the incident as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the volume of data taken, the number of systems affected, or the precise date the intrusion began. The count of people whose information may have been involved is listed as unknown. Method of initial access, dwell time, and whether encryption was also deployed on production systems have not been disclosed in the material provided.

Because the primary public signal is the group’s own leak-site listing, the claim that files were removed must be treated as an assertion by the threat actor until the agency or an independent investigation states the scope. No dollar amounts, file counts, or specific document titles appear in the reported facts.

Inside ransomhouse

Ransomhouse is a ransomware operation that has been publicly documented since roughly 2022. Like many contemporary groups, it typically follows a double-extortion model: data is copied from the victim’s network before or during encryption, and the group then threatens to publish the material on a dedicated leak site if a ransom is not paid. Listings on such sites serve both as pressure on the victim and as advertising of the group’s activity. Public reporting on ransomhouse has described the use of custom or affiliate-deployed encryptors, data-exfiltration tools, and negotiation channels that remain active for days or weeks after the initial claim.

The group has previously listed organisations across multiple sectors and jurisdictions; those earlier listings form part of the open-source record of its behaviour. None of that prior activity, however, supplies independent verification of the specific files or systems said to have been taken from the Swedish Arts Council. Any statements appearing on the leak site about this particular victim remain claims by the group.

Swedish Arts Council and its sector

Kulturrådet is a Swedish government agency charged with promoting the development of culture, providing information, and granting funding to realise national cultural policy. Its remit covers music, literature, visual arts, performing arts, and support for children and youth; it also works to strengthen international collaboration and cultural exchange, including through programmes such as Creative Europe. As a public body it sits at the intersection of cultural policy, grant administration and information services.

Agencies of this type routinely process applications from individuals and organisations, maintain correspondence with artists and cultural institutions, and hold administrative records required for the transparent allocation of public money. A breach affecting such an organisation therefore touches both the machinery of cultural funding and the personal and professional data of people who interact with that machinery. The sector as a whole has seen increased attention from ransomware operators in recent years because public agencies often manage large volumes of structured records and face strong incentives to restore services quickly.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or record categories has been publicly named. The number of individuals potentially affected is unknown, and exact contents remain unconfirmed.

Organisations that administer cultural grants and policy typically hold, among other material, application forms, contact details of applicants and staff, project descriptions, financial documentation related to awards, and internal working papers. Whether any of those categories were among the files claimed by ransomhouse cannot be established from the available record. Readers should therefore treat the exposure of any particular personal or organisational data as unconfirmed until official notification or forensic reporting provides clarity.

Why it matters

For individuals whose information may have been present in the exfiltrated material, the concrete risks include unwanted contact, social-engineering attempts that reference genuine grant or correspondence details, and longer-term misuse of personal identifiers if such data were included. For cultural organisations that rely on the agency for funding decisions, disruption of internal systems or leakage of sensitive project information can affect planning, confidentiality of applications, and trust in the grant process.

For the Swedish Arts Council itself, the incident raises operational and reputational questions common to public bodies: the need to restore or verify the integrity of systems, to notify data subjects where required by law, and to maintain continuity of cultural-support services while investigations proceed. Because the scale remains undisclosed, the precise severity of these risks cannot yet be quantified; the absence of confirmed numbers does not eliminate the possibility of impact.

Were you affected?

If you have submitted grant applications, correspondence or other personal information to the Swedish Arts Council, monitor official communications from the agency for any notification. Consider placing fraud alerts with relevant credit or identity services if you later learn that financial or identity documents were involved. Change passwords on any accounts that reused credentials potentially stored by the organisation, and remain alert to phishing messages that reference cultural funding or the agency by name.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a check does not confirm or rule out involvement in this specific incident, but it provides a practical baseline for further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySwedish Arts Council security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Swedish Arts Council’s full breach history →

More recent breaches

[Internal database pack 4] Warren County Sheriff’s Office Listed by ransomhouse Ransomware GroupDecember 20, 2025Fedcap Listed by ransomhouse Ransomware GroupDecember 10, 2025Lawsoft Listed by ransomhouse Ransomware GroupDecember 1, 2025Public Safety Mutual Benefit Fund Listed by ransomhouse Ransomware GroupNovember 4, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Swedish Arts Council Listed by ransomhouse Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by ransomhouse — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram