Inission Power Finland Oy and Inission Power Oy have been affected by a data breach in which personal information from parts of the companies' databases has been published online.
The breach was discovered on June 22, 2026. According to the company's technical investigation, it is a ransomware attack.
The affected server environment was isolated and restored the same day. Inission states that operations have been able to continue normally and that the incident did not cause any significant impact on ongoing operations.
Databases found published
According to Inission, the initial investigation did not provide any reason to suspect that information had been removed from the environment. However, further investigation revealed that parts of the affected databases had been published online.
The company cannot rule out that the attackers have obtained additional information or that more material may be made public.
The data concerned may include, among other things:
- Name and contact information.
- Finnish personal identification numbers.
- Bank account number and salary details.
- Information about union membership.
- Data from development and performance discussions.
- Health-related personal data.
- Information from older shareholder and insider registers.
The information may be found in personnel files for current and former employees. Inission says some of the documents date back to 2000.
Older shareholder registers are affected
The incident also includes shareholder registers belonging to Efore Oyj during the period 2005-2018 and Enedo Oyj during 2021-2022.
The registers may contain names, addresses, personal identification numbers and information about shareholdings.
Information from an insider register between 2007 and 2017 may also have been affected. This may include information about relatives of current and former board members.
Initiation has contacted identified individuals when sufficient contact information was available. Since it has not been possible to reach all affected individuals individually, the company has also published a public notice.
The incident has been reported to authorities.
The data breach has been reported to the Finnish Data Protection Ombudsman's Office and the Cybersecurity Center at Traficom. A police report has also been filed.
Individuals whose information may have been exposed are urged to be especially vigilant for phishing, fraud attempts, and unexpected contacts where the sender already knows personal information.
Leaked identity and banking information can be used for identity theft, targeted social manipulation, and financial fraud. Inission therefore recommends that affected individuals monitor their accounts and credit information and not disclose further information via unexpected links or phone calls.
The company states that the public information will be updated if the investigation shows that more categories of information or additional people have been affected.
More information
A more detailed notice of the data breach, including information on the groups affected, the types of data that may have been affected, possible consequences, and recommended safeguards, can be found at:
For more information: Inissionpower.com
Inission Power regrets any damage or inconvenience the incident may cause.
