Uploaded August 2026 | Updated September 2026, 7 hours ago
Fighting Back Against Large-Scale Phishing Campaigns Targeting Swedish Municipalities, Regions and Schools
Mathias Persson (CERT-SE, SE)
Between June 2024 and May 2025, CERT‑SE observed an alarming surge in phishing attacks aimed at Swedish municipalities, regions, and schools. These campaigns were not only widespread but highly persistent, exploiting compromised M365 accounts to spread malicious emails internally and externally. The impact included reputational damage and, in some cases, financial fraud, as well as an increased risk of data breaches.
In this presentation, we will share how CERT‑SE analyzed these attacks, uncovering common patterns and tactics used by threat actors. More importantly, we will tell the story of how collaboration became the key to an effective response. By partnering with SKR (Swedish Association of Local Authorities and Regions), we developed and distributed a practical guide for handling compromised accounts in M365 environments. This initiative helped organizations regain control and implement proper remediation steps.
Attendees will gain insight into the anatomy of these phishing campaigns, lessons learned from large‑scale incident coordination, and actionable recommendations for improving resilience in similar environments.
---
Mathias Persson is a cybersecurity specialist at CERT-SE, Sweden’s national Computer Security Incident Response Team. Passionate about collaboration and practical solutions, Mathias works closely with municipalities, regions, and national stakeholders to strenghten resilience against evolving threats. In this session, Mathias shares real-world insights from a year-long battle against persistent phishing campaigns and the lessons learned from building effective partnerships.
Fighting Back Against Large-Scale Phishing Campaigns Targeting Swedish Municipalities, Regions and Schools
Mathias Persson (CERT-SE, SE)
Between June 2024 and May 2025, CERT‑SE observed an alarming surge in phishing attacks aimed at Swedish municipalities, regions, and schools. These campaigns were not only widespread but highly persistent, exploiting compromised M365 accounts to spread malicious emails internally and externally. The impact included reputational damage and, in some cases, financial fraud, as well as an increased risk of data breaches.
In this presentation, we will share how CERT‑SE analyzed these attacks, uncovering common patterns and tactics used by threat actors. More importantly, we will tell the story of how collaboration became the key to an effective response. By partnering with SKR (Swedish Association of Local Authorities and Regions), we developed and distributed a practical guide for handling compromised accounts in M365 environments. This initiative helped organizations regain control and implement proper remediation steps.
Attendees will gain insight into the anatomy of these phishing campaigns, lessons learned from large‑scale incident coordination, and actionable recommendations for improving resilience in similar environments.
---
Mathias Persson is a cybersecurity specialist at CERT-SE, Sweden’s national Computer Security Incident Response Team. Passionate about collaboration and practical solutions, Mathias works closely with municipalities, regions, and national stakeholders to strenghten resilience against evolving threats. In this session, Mathias shares real-world insights from a year-long battle against persistent phishing campaigns and the lessons learned from building effective partnerships.










