It's described as blackmail that stopped institutions from doing their work, so possibly an encryption virus? The German police had an IP going to Mullvad so it kinda makes sense that they would ask Swedish police to get info on who used it? Would be an error on their part to not follow the lead?
Well my point was, if German police is making international requests to check out a vpn provider based on an ip from 2 years ago, probably they're running out of ideas at that point, possibly even aware that the data is no longer there, and just responding to political pressure to "do something".
Mullvad even pointed out that Swedish police are well aware at this point that there's no useful information for them there. That's why I think probably it's just to appease some politican or DA somewhere, or some other type of strange bureaucratic machination.
Investigations take time. It's possible that they managed to get a disk dump of a compromised server and found a Mullvad config file, for instance, and they were just trying to follow the trail back to the criminals that carried out the attack.
I'm guessing the authorities were hoping that Mullvad lies about their no logs policy, like some cheap VPN providers do.