Skip to content
Security Notes

Vastaamo: when stolen therapy notes became individual extortion

By Elias Lankinen11 min read

Now I'll write the post.

The email that arrived in tens of thousands of inboxes

In late October 2020, roughly thirty thousand Finns opened an email that told them their therapist's notes were about to be published. The message was blunt. Pay 200 euros in bitcoin within 24 hours, and the sender would keep quiet. Miss the deadline and the price rose to 500 euros. Ignore it entirely, and everything you had ever said in a therapy session, the affairs, the suicidal thoughts, the childhood abuse, the fears you had never told anyone else, would be posted online with your name and home address attached. This was not a hypothetical threat. The sender already had the files, and had already started publishing them. Finland was watching its largest and most intimate data breach unfold in real time, patient by patient. The company at the centre of it, a private psychotherapy chain called Vastaamo, would be bankrupt within four months. The story that followed ran for six more years and is, as of this writing, still not fully over.

Source: Steve Jurvetson, via Wikimedia Commons
Source: Steve Jurvetson, via Wikimedia Commons

What Vastaamo was, and why the data was so sensitive

Vastaamo, whose name means roughly "the place that answers," was founded in 2008 and grew into one of Finland's largest private mental health providers, running around 25 clinics and handling therapy that the public health system paid for. That last detail matters: because Vastaamo was plugged into the national health insurance system, ordinary people were routed to it. These were not wealthy clients paying out of pocket for boutique care. They were teachers, nurses, teenagers, police officers, and civil servants who went where the system sent them. Their records held the most sensitive category of personal data that exists. A leaked credit card can be cancelled and reissued. A password can be changed. A verbatim transcript of what you told a psychologist about your marriage, your addictions, or your abuser cannot be un-leaked, and it cannot be changed. According to the English-language reporting compiled on the case, the stolen files contained full names, home addresses, Finnish personal identity codes (the national ID number used for banking, taxes, and healthcare), the names of clinics, and the therapists' own session notes, which described things like adulterous relationships, suicide attempts, and paedophilic thoughts. That combination is the whole story in miniature. The identity code makes each person findable and impersonable. The notes make them exposed. Put the two together and you have a weapon aimed at an individual.

How a therapy clinic left its front door open

Here is the misconception worth killing early. Most people hear "hacked" and imagine a sophisticated ransomware crew burning through defences with custom malware. Vastaamo was almost the opposite. It was a case of basic negligence so severe that "hacking" almost overstates the effort involved. According to the Finnish Data Protection Ombudsman's ruling, the patient database sat on a server that was exposed to the open internet, with no firewall in front of it, from November 2017 until March 2019. The database's MySQL port was reachable from anywhere, and the root account, the master administrator login that controls everything, had no password set at all. The sensitive notes were stored in plain text, not encrypted and not anonymised. In practical terms, anyone who scanned that range of internet addresses and knocked on the right port could walk straight in. That is what happened. Forensic investigators from the security firm Nixu, who examined the wreckage in October 2020, concluded that an outside party logged into the database without authorisation at least twice, in November or December 2018 and again in March 2019. The attacker used ordinary network-scanning tools to find the exposed server, which had been set up for remote access in 2017 with none of the standard protections a healthcare provider is expected to use: no VPN, no multi-factor authentication, no password policy. There is a second, darker layer to the negligence, and this is where the timeline becomes damning. The March 2019 intrusion did not go unnoticed forever. The database was tampered with and an extortion message was left behind, which strongly suggests the company had reason to know it had been breached in the spring of 2019. Yet Vastaamo did not tell the Data Protection Ombudsman, and did not tell its patients, until the crisis went public in the autumn of 2020. The Ombudsman's finding was explicit that Vastaamo should have reported the breach "without delay, because the violations resulted in a high risk to the data subjects." Instead there was roughly an eighteen-month silence.

From extorting a company to extorting the patients

The public phase began in late September 2020, when someone using the handle "ransom_man" contacted Vastaamo and demanded 40 bitcoin, worth around 450,000 euros at the time, in exchange for not releasing the database. The company did not pay. What came next is what made this case genuinely new. When the corporate extortion failed, the attacker went around the company and straight to its patients. He began leaking files onto a Tor hidden service, the sort of dark-web forum reachable only through anonymising software. Hundreds of individual patient records went up, and a roughly 10-gigabyte archive containing the notes of at least 2,000 people circulated. Then the mass emails went out: pay a small individual ransom, or your file is next. The scale is worth sitting with. Somewhere between 24,000 and 33,000 people were affected, and, as reported at the time by Malwarebytes, more than 20,000 received the individual demands. This was extortion at industrial scale, but each message was crafted to feel personal, because it was. The leverage was not a locked file the victim could restore from backup. The leverage was shame, aimed at people who had gone to therapy precisely because they were already struggling.

Source: Pöllö, via Wikimedia Commons
Source: Pöllö, via Wikimedia Commons

A whole country responds

On 21 October 2020, Vastaamo confirmed the breach publicly, and Finland reacted the way a small, high-trust society reacts when its trust is violated at scale. Tens of thousands of people filed police reports, making it one of the largest criminal cases the country had ever seen by number of victims. The government convened emergency meetings. Crisis helplines were stood up specifically for Vastaamo patients, an unusual admission that the harm here was psychological first and financial second. One concrete policy change stands out because it broke a long-standing taboo. The Finnish personal identity code was designed to be permanent, a number you keep for life. After Vastaamo, the government moved to let citizens change that code in cases where it had been compromised and posed a serious risk of harm, something that had essentially never been allowed before. It was a tacit acknowledgement that a piece of "permanent" national infrastructure had been turned into a liability. The human cost is the hardest part to state precisely, and it deserves care rather than false confidence. A lawyer representing victims reported that at least two suicides were linked to the exposure, and others attempted to take their own lives. Linking a suicide to a single cause is genuinely difficult, and these figures come from victims' advocates rather than a court finding, so they should be read as reported associations rather than proven causation. What is not in doubt is that thousands of already-vulnerable people were told, by a stranger, that their worst secrets were for sale.

The company collapses, and the CEO's role is contested

Vastaamo itself did not survive. It was declared bankrupt in February 2021, its therapy operations were transferred to another provider, Verve, and in December 2021 the Data Protection Ombudsman imposed an administrative fine of 608,000 euros for the security failures and the failure to report the breach in time. The fate of Vastaamo's chief executive, Ville Tapio, is where the story resists a tidy moral. Tapio was removed from his role in October 2020, and prosecutors argued he had known about the earlier breach and concealed it. In April 2023 he received a three-month suspended sentence for a data protection offence. But on appeal in December 2025, a court cleared Tapio, finding insufficient evidence of the gross negligence the charge required. Whether that reads as vindication or as a gap in the law depends on your view, but it is a reminder that "someone was obviously negligent" and "a specific person can be convicted for it" are not the same sentence.

The hunt for ransom_man

The person behind the handle turned out to be one of the most notorious figures in European cybercrime. According to Wikipedia's profile and contemporaneous reporting, he is Aleksanteri Kivimäki, born in Espoo in 1997 and known online for years as "zeekill." As a teenager he had been part of the Lizard Squad collective that knocked the PlayStation Network and Xbox Live offline at Christmas 2014, had made swatting calls against American families, and had once phoned in a fake threat that diverted an American Airlines flight. In 2015, still a minor, he pleaded guilty to more than 50,000 counts of computer crime and received only a suspended sentence. He was, in other words, a repeat offender who had learned that consequences were survivable. Investigators caught a break from the leak itself. When the attacker published the stolen data, the archive reportedly contained material that should not have been there, including files that helped tie ransom_man back to Kivimäki, alongside an IP address linking the two identities. In October 2022 the Finnish National Bureau of Investigation publicly named him and an Interpol Red Notice was issued. His whereabouts were unknown; he had been living in France under a false identity, with time in Saint-Tropez and a residence in London. The arrest, when it came in February 2023, was almost farcically mundane. French police in Paris responded to a domestic disturbance call, found a man carrying forged identity documents and living under a fake name, and only afterward realised who he was. He was extradited to Finland later that month.

Source: Massimiliano Mariani, via Wikimedia Commons
Source: Massimiliano Mariani, via Wikimedia Commons

Following money that was supposed to be unfollowable

The most technically interesting thread in the case is how the money was traced, because it punctures another common belief: that cryptocurrency makes ransom payments untouchable. During the investigation, police made a small, deliberate bitcoin payment to the extortionist's account and then followed where it went. The attacker tried to break the trail by converting funds into Monero, a privacy coin specifically designed to hide transaction amounts, senders, and receivers, and then converting back into bitcoin. Monero is widely regarded as far harder to trace than bitcoin, whose ledger is public. Yet according to BleepingComputer's reporting, Finnish investigators, working with the exchange Binance, followed the payments through the Monero conversion and back to Kivimäki's own bank account. Crucially, the National Bureau of Investigation declined to explain exactly how it de-anonymised the Monero leg, citing the need to protect a technique it might use again. That silence is itself significant. It leaves open whether Monero was truly cracked or whether the trail was reconstructed through exchange records and human error at the edges, where private coins get swapped for ordinary ones. Either way, the operational lesson for anyone tempted to think "I'll just use a privacy coin" is that the anonymity tends to fail at the boundaries, when crypto meets a regulated exchange or a real bank account.

The verdict, the appeal, and a wanted man again

The charges give a sense of the scale the court was dealing with. Kivimäki was tried for aggravated computer break-in, thousands of counts of disseminating information that violated personal privacy, more than 20,000 counts of attempted aggravated extortion, and 20 counts of completed aggravated extortion, corresponding to the small number of patients who actually paid. In April 2024 the Western Uusimaa District Court convicted him and sentenced him to six years and three months in prison. Then the case took a turn that frustrated many victims: in September 2025, while his appeal was pending, the Court of Appeal released him from custody on the grounds that he had already spent a long time in pre-trial detention. In February 2026 the appeal court actually increased his sentence to six years and eleven months, one month short of the statutory maximum, finding that the crimes were carefully planned, aimed at an exceptionally large number of vulnerable people, and driven by financial gain. The final twist is almost too neat. In July 2026 Finland's Supreme Court refused to hear his appeal, making the sentence final. But by then Kivimäki was no longer in prison and, according to his own lawyer, was believed to be abroad. With roughly five months left to serve, Finnish police issued a wanted notice and instructions to detain him on sight. The man who spent years hiding under a false name may be doing so again.

What Vastaamo actually changed

It is tempting to file this under "cybersecurity horror story" and move on, but the more useful reading is about incentives. The technical failure was trivial and cheap to fix. A firewall, a password on the root account, and encryption of the notes would have cost Vastaamo almost nothing. What was expensive was caring enough to do it before something went wrong, and the eighteen-month silence after the 2019 breach suggests the company's instinct was to hide the problem rather than absorb the cost of admitting it. The regulatory response, a 608,000-euro fine against a bankrupt company, arrived far too late to protect anyone. The deeper shift Vastaamo forced is conceptual. It made a whole country treat mental health records as critical infrastructure, data whose exposure can end lives rather than just empty bank accounts, and it proved that the target of a breach can be a single frightened person rather than an institution. The academic literature has caught up: a 2026 study in a Sage journal frames Vastaamo as a turning point in how we think about breaches at healthcare providers. The open question is whether the lesson generalises beyond Finland. Therapy notes, genetic data, fertility records, and location histories are all being collected at scale by companies whose security is only as good as their cheapest quarter. Vastaamo showed exactly how the attack works and exactly how little it takes to enable it. The uncomfortable part is that the fix was known the whole time, and someone chose not to pay for it.

Sources

  1. Wikipedia, Vastaamo data breach, 2026.
  2. Wikipedia, Aleksanteri Kivimäki, 2026.
  3. Office of the Data Protection Ombudsman (Finland), Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations, 2021.
  4. Malwarebytes Labs, Vastaamo psychotherapy data breach sees the most vulnerable victims extorted, 2020.
  5. The Register, Finland psychotherapy clinic ransom attack, 2020.
  6. The Record (Recorded Future News), Finland issues wanted notice for hacker behind massive psychotherapy data breach, 2022.
  7. BleepingComputer, Vastaamo hacker traced via 'untraceable' Monero transactions, police says, 2024.
  8. BankInfoSecurity, Finnish Vastaamo hacker freed while appealing conviction, 2025.
  9. Helsinki Times, Kivimäki sentence increased to nearly seven years in Vastaamo case, 2026.
  10. Helsinki Times, Vastaamo hacker wanted after appeal rejected, 2026.
  11. Helsinki Times, Court clears former Vastaamo CEO Ville Tapio of data protection charges, 2025.
  12. Ghanbari, H. and Koskinen, K., When data breach hits a psychotherapy clinic: The Vastaamo case, Digital Health (SAGE), 2026.