Yaamlabs
Ransomware

Svedala's IT shutdown: running care when all is offline

A Swedish municipality switched off every system after a suspected ransomware intrusion. What is known, and how to keep care running when IT is gone.

By Yaali. October 5, 2026, 7 min read, Ransomware, Resilience.

Cover illustration of a dark town hall at night with a desk lamp lighting a clipboard and a stack of binders beside an unlit server rack, with the Yaamlabs logo and the text: Svedala switched off every system to stop an intruder, October 1, home care moved to paper binders

Svedala, a municipality in Skåne just southeast of Malmö in southern Sweden, shut down all of its IT systems in the night going into Thursday, October 1. An outside attacker had got into the municipal network and tried to take data. Municipal director Johan Lundgren told SVT it appeared to be a ransomware attack. The municipality activated its crisis management, police are investigating alongside its IT department, e-services and email stopped working, and home care and elderly care switched to paper.

Four days on, the important facts about the attack itself are still missing. Svedala has not said how the attacker got in, no ransomware group has publicly claimed it, and there is no date for systems to return. No ransom demand had arrived when the municipality first reported the attack. In a later update Lundgren said that "with high probability" some information may have disappeared or leaked, while the technical analysis was still running. For any council, care provider or small organisation, the useful part of this story is what had to keep working while everything was off.

What Svedala has confirmed since the night of October 1, which services kept running and what is still unknown

What Svedala has said so far

The intrusion was caught while it was happening. The municipality says someone from outside had access to its IT environment and was trying to reach information, and it switched off every digital system to limit the damage.

Residents were pointed to a temporary website and to the telephone switchboard, which stayed staffed. Schools and preschools kept running as normal. Home care and elderly care moved to analogue routines the municipality says it updates every day, with paper documentation on each person receiving care so that the right medication goes to the right person.

Svedala has also said what it is doing now: working out where the attacker got in and checking whether anything was left behind on its systems. Ransomware crews usually leave remote access tools, new accounts or scheduled tasks behind, and restoring onto a network that still holds them invites a second round.

This has happened to Swedish municipalities before

Kalix, in Norrbotten, was hit by ransomware on December 16, 2021. Home care staff lost access to care records and medication lists, salary payments were disrupted, and the municipality refused to pay. In January 2024 an Akira ransomware attack on one of Tietoevry's Swedish data centres took down services for municipalities, universities, government agencies and companies that relied on the provider, including the Primula payroll and HR system used by government agencies, universities and colleges.

In Svedala the shutdown was the municipality's own decision, made to stop an intrusion it could see, and not the result of encryption or a supplier outage.

Deciding to pull the plug

Shutting down everything costs services; leaving systems running risks the attacker reaching backups, domain controllers and the hypervisors that host them. The choice is easier when the conditions are written down in advance: who can order it (a named role with a deputy, reachable in the middle of the night), and which triggers justify it, such as confirmed interactive access by an outsider, encryption starting on any server, or signs of data being staged for upload.

The US Cybersecurity and Infrastructure Security Agency (CISA) #StopRansomware guide says to isolate affected systems first and to power devices down only when you cannot disconnect them from the network. Cutting power wipes volatile memory, and with it the running processes, network connections and encryption keys that investigators often need. Where you can, pull network links at the switch or firewall, or isolate hosts through your endpoint detection and response (EDR) console, and leave the machines on.

Before anything is rebuilt, preserve:

  • Memory captures and disk images from a sample of affected servers and workstations, including virtual machines
  • Firewall, VPN and remote access logs, which are often the only record of the way in
  • Windows Security event logs and domain controller logs, especially sign-ins (event ID 4624), new accounts (4720) and group membership changes (4728, 4732)
  • EDR telemetry and alerts, exported before any console or tenant is reset
  • Any ransom note, unknown binaries and scripts, with the paths where they were found

Write down who took each copy, when, and where it is stored, since police are part of the investigation.

Keeping care running with no IT

A home care worker without the schedule does not know which door to knock on, and one without the medication list cannot safely give a dose. Svedala's care staff kept working because the paper copies already existed and were kept current; in Kalix in 2021, staff lost both.

A continuity pack for a municipality or care provider: what to keep offline, what to do in the first hours, and the order to restore services in

What belongs in the offline pack:

  • Care plans and medication lists for every person receiving care, printed or exported on a schedule and stored at each unit
  • Visit schedules and routes for home care for the coming days
  • A contact list for staff, managers, on-call nurses, pharmacies, the IT supplier and the police, on paper and in personal phones
  • The incident response plan itself, since CISA says to keep a hard copy and an offline version
  • Logins for the systems you will need on a clean device, such as the backup console and the domain registrar, held in a sealed or offline password store

If staff chat, email and voice over IP (VoIP) phones all depend on the same directory and network, an attacker may be reading them, and a shutdown takes them all away. CISA recommends out-of-band methods such as phone calls to coordinate isolation without tipping off the attacker: mobile phones with a pre-agreed call tree, and a messaging group that does not sign in through your main identity provider.

Bringing services back in order

Restore in an order decided before the incident. CISA ties it to a predefined critical asset list that puts health and safety systems first. For a municipality that usually means a clean identity system first, then care documentation and the safety alarms in elderly housing, then payroll and the systems that pay suppliers and benefits, and only then e-services and everything else.

Identity comes first because every other system trusts it. Reset passwords for all affected accounts, including service accounts, and reset the Kerberos krbtgt account twice, letting replication finish between resets, so that forged Kerberos tickets stop working. Restore from backups taken before the earliest sign of intrusion, and scan restored systems for the persistence Svedala is now looking for before they go back on the network. Expect paper records from the downtime to need entering into the care system afterwards.

Swedish municipalities also have a reporting clock. Under the cybersecurity law that brings the EU's NIS2 directive into Swedish law, a significant incident needs an early warning to the national cybersecurity centre (NCSC) within 24 hours of detection, an incident notification within 72 hours and a final report within a month. Personal data loss is a separate report to the data protection authority (IMY). Put both deadlines in the plan.

What to do this month

Check that your care units have a printed, current copy of every care plan and medication list, and pick a date to test it: switch a home care team to paper for one shift and see what they cannot find. Write down who can order a full shutdown and what triggers it. Then make sure your logs reach somewhere an attacker cannot delete them and are kept long enough to show how someone got in weeks earlier.

Our security operations team watches for the early signs of an intrusion and helps with containment and evidence, and our safeguarding and hardening work covers the identity, logging and recovery setup a shutdown depends on. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would run the work.


Sources: Sveriges Radio, Sveriges Radio follow-up, Göteborgs-Posten, SVT, SVT on elderly care, eBuilder Security, Sejfer, Blckit, SVT on Kalix, Suntarbetsliv on Kalix, BleepingComputer on Tietoevry, Help Net Security on Tietoevry, CISA #StopRansomware Guide, NCSC Sweden incident reporting, PTS incident reporting.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.