Swedish authorities have opened an investigation into an alleged leak involving development materials tied to the country’s e-government infrastructure. Claims circulating on cybersecurity forums and social media say a threat group called ByteToBreach released files connected to CGI Sverige, raising concerns about possible exposure within digital public services used by millions of people.
Leaked files are said to include source code and internal documentation
According to Aftonbladet, the material may involve components linked to Sweden’s digital public services platform. CGI Sverige, the Swedish unit of CGI Group, supports several government systems used across the country. Reports around the alleged dump say the exposed material may include not only source code, but also configuration files and internal documentation. Security analysts said files of that kind can reveal how systems are structured.
CGI said the incident concerned two internal testing servers, not active production systems. The company said those servers contained an older version of an application together with related source code. CGI press secretary Agneta Hansson told Aftonbladet that Swedish authorities are reviewing the matter. The company also said its investigation found no signs that operational services or customer production data were affected.
Government agencies and cyber units are reviewing the case
Swedish civil defense minister Carl-Oskar Bohlin confirmed that the government is analyzing the incident. Authorities are working with CERT-SE and the National Cyber Security Center as the review continues. At this stage, investigators have not verified the full contents of the alleged data dump, and the exact scope of the exposure remains under assessment.
IT security specialist Anders Nilsson reviewed samples of the files circulating online. He said early findings suggest the material appears authentic and includes what looks like source code tied to several programs. Based on the evidence currently available, Nilsson said the breach claim may be genuine.
Researchers warn exposed code can be used to identify weaknesses
Sweden relies heavily on e-government services. Eurostat data shows that in 2024, about 95% of the country’s 10.7 million residents used those services. That makes any development leak more serious. Cybersecurity researchers warned that attackers often study exposed code and supporting files to locate weaknesses in live infrastructure.
Threat intelligence platform Threat Landscape said the activity may fit a broader pattern. The group noted that ByteToBreach had previously claimed responsibility for a breach involving Viking Line. Analysts believe these incidents may be part of a wider campaign targeting infrastructure in Sweden and elsewhere in Europe, with CGI’s managed services network seen as a possible strategic target.
Claims about personal data remain unconfirmed
Investigators have not confirmed what the alleged leak contains in full. Some reports say the files may include internal staff databases and electronic signing documents. The threat actor also claimed to hold personally identifiable information connected to citizens, but Swedish authorities have not confirmed that such data is part of the leaked material.
Authorities and cybersecurity agencies in Sweden are continuing to assess the reported breach, verify the data involved, and identify the individuals behind the intrusion.

