Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Hacker Claims 1.49 Million Swedish Business Records for Sale

Hacker Claims 1.49 Million Swedish Business Records for Sale

Last updated:September 24, 2026
Human Written
  • A forum user allegedly offered 1.49 million Swedish business records for sale.

  • The claimed database contains emails, phone numbers and company information.

  • The source of the dataset, accuracy and legality remain unverified.

Hacker Claims Swedish Business Database With 1 49 Million Records are for Sale

A forum user has allegedly put a large Swedish business database up for sale, claiming it contains 1,495,005 records collected from Hitta.se. The listing describes the material as fresh B2B data and says it covers businesses across Sweden.

The offered package contains emails, telephones numbers, organization identifying numbers, and company information. However, it is unconfirmed without third-party evidence that the provided list is from Hitta.se and listed data is true.

Forum Listing Claims More than 1.4 Million Records

The seller, using the handle ‘NodeScraper,’ reportedly lists the dataset as a Sweden Business Database. The post gives a claimed total of 1,495,005 records. It also lists 746,073 email records and 414,525 phone records. The seller claims 616,902 unique email addresses and 351,973 unique phone numbers.

The advertised fields reportedly include company or legal name, organization number, legal form, address, ZIP code, city, business category, phone number, and email address. Website details and geographic coordinates also appear in the claimed dataset description.

The seller says the information came directly from Hitta.se. The listing gives September this year as the collection date and offers the database commercially. That claim needs careful handling. A forum post alone cannot prove where a database came from. It also cannot establish whether every record remains current or whether the seller actually controls the advertised data.

Hitta.se describes itself as one of major channels for customers looking for businesses in Sweden. The company says its platform receives about 400 million visits each year.

What the Claimed Dataset Could Contain

The listed fields matter because they combine several pieces of business information in one package. A single record could potentially connect a company name with an organization number, address, phone number, email address and website.

Some records may describe businesses rather than private individuals. But contact information about a business can reveal about real persons, especially if the record contains the direct phone number of the people or their email addresses.

Sweden implements the General Data Protection Regulation of the European Union. The Swedish Authority of Privacy Protection states that a company processing personal information needs to follow legal terminology and ideas of GDPR. The firm must also provide security for the personal information it processes.

The European Data Protection Board states that a breach of personal data involves an illegal access or disclosure of the personal data. Such incidents can create risks including identity theft and fraud.

Therefore, the status of the advertised information matters. If the dataset contains only publicly listed company information, the legal and privacy questions may differ from a package containing private contact details.

The listing does not establish that distinction. It also does not show whether the information was collected lawfully, whether Hitta.se authorized the collection, or whether the seller obtained it through a security incident.

Scraping Claim Raises Questions About Source and Legality

The seller allegedly stated they scraped the database from Hitta.se. Web scraping involves collecting data from websites automatically, but that gives no proof of stealing the dataset. Hitta.se publishes information about how it handles privacy and user data. Its official site also provides information about its services and terms.

The source claim raises questions about whether the data matches information available on Hitta.se. Investigators would need to establish when the collection happened.

They would also need to examine whether the database contains information that was not publicly available. That distinction could help show whether the seller merely copied public records or obtained data through another route.

Meanwhile, the claimed September collection date makes the allegation current. Yet the date remains part of the seller’s description, not an independently confirmed fact.

Swedish privacy rules can apply when organizations process personal data, even if the information appears online. IMY says organizations must follow GDPR when they process personal data and must protect that information.

Thus, commercial selling of the scraped database might incur privacy and compliance issues, considering the inclusion of personal data. However, the exact legal situation would depend on data type, sources, purpose of usage, and other parties involved.

What Happens If the Data is Genuine?

If researchers or authorities confirm the dataset, they would need to establish its scope and origin. They could compare sample records against known public listings.

If the dataset has been obtained through unauthorized means, the impacted organizations can have additional responsibilities. GDPR outlines that organizations must adopt technical and operational measures for data protection. Some types of breaches are also required to inform the relevant data protection authority within 72 hours once discovered.

However, adherence to these requirements will hinge on governing authorities recognizing the incident as a personal data breach and assessing who was in control of the compromised data. Currently, the claims from the seller about the database are still unsubstantiated. The supplier did provide numbers and a claimed source; however, this still does not make it authentic.

This particular case illustrates why databases that have a comprehensive collection of business information may attract attention from hackers. The security risks can become even greater when organizations give automated systems broader access to sensitive data. Our report, AI agents raise new security risks as companies hand them greater access, examines how expanded access for AI agents can create new security challenges.

Also, public business information may become more valuable if put together in one searchable database. More proof will be available before the information in the database can stand as evidence of a data leak involving Hitta.se or Swedish businesses.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.