This report examines the evolving cyber threat landscape facing Sweden following its accession to NATO. It was developed in response to a surge in cyberattacks against the country: 2025 was a record year for both the volume and sophistication of threats directed at Swedish institutions, critical infrastructure, and private sector entities.
The analysis arrives at a moment of strengthening bilateral relations between Poland and Sweden, underlined by the Swedish royal visit to Poland in March 2026.
The NATO accession ended over 200 years of Swedish military non-alignment, and the report’s core assessment is that the country now operates in an elevated and persistent threat environment, driven primarily by its NATO membership.
What the Report Covers
The analysis is based on Baysec CTI platform data, open-source reporting, and assessments from Swedish government and security institutions. It is organised into four parts:
- Geopolitical context - Sweden’s NATO accession, how it reshaped the country’s threat profile, and Sweden’s continued support for Ukraine.
- State-level threats - state-sponsored activity including the relevant APT groups, espionage cases, and information influence operations.
- Major cyber incidents - the significant attacks of 2025, ransomware activity, the threat actors most active against Sweden, and an assessment of the most targeted sectors.
- Business perspective - the cybersecurity posture of Swedish companies and what the current threat environment means for them.

Access the Report
The full Sweden - Cyber Threat Landscape Following NATO Accession report is a Baysec Exclusive, available on the Baysec Platform or through the Baysec Newsletter. For inquiries, contact kontakt@baysec.eu.