Case file · VASTAAMO 2020

What happened in the Vastaamo breach: therapy records held for ransom, one patient at a time

Published 2026-09-29 · 5 min read · Missing control: Access control on sensitive databases

In October 2020 roughly 30,000 people in Finland opened an email demanding money to keep their own psychotherapy notes off the internet.[2] This case file covers how a private therapy provider's patient database was copied 2 years earlier without anyone noticing, how the extortionist was caught and sentenced, and the one control that would have kept the records out of reach.

What happened

Vastaamo was a private psychotherapy provider with clinics across Finland. In November 2018 someone got into its patient database and copied it, and there was a second intrusion in March 2019.[2][3] The records covered about 33,000 patients and included names, national identity numbers, contact details and therapists' notes from sessions.[1][3] The breach went unnoticed for about 18 months.[4]

In autumn 2020 the extortionist contacted the company and demanded 40 bitcoin, then worth about €450,000, to keep the data private.[2][3] When the company would not pay, batches of patient records were posted on a hidden website and, in late October 2020, emails went out directly to patients.[1][4] Each demanded €200 in bitcoin within 24 hours, rising to €500 after that, or their notes would be published.[2]

Finnish police told victims not to pay, keep the evidence and file reports, and a crisis line was set up.[4] About 20 patients paid anyway.[1] The fallout was severe: the chief executive was removed on October 26, 2020, after it emerged he had known about the March 2019 intrusion and kept it from the board, authorities and patients, and the company was declared bankrupt in February 2021.[2][3]

How they got in

Vastaamo's patient system kept everything in one database that was reachable over the internet. Prosecutors said the intruder used a compromised login to connect to that database server and download the records.[5] Once inside, nothing else stood in the way. The sensitive data was stored without encryption and without being separated from identifying details, and the system's top-level administrator account had no password set at all.[2]

In plain terms, the most private information a person can share with a professional sat in a single store with the door propped open, and nobody was watching who came and went. That is why a copy made in 2018 could be used for blackmail in 2020.

How it was caught

Finnish police named a suspect, Aleksanteri Kivimäki, in October 2022. He was arrested in France in February 2023 and returned to Finland that same month.[1][2] Prosecutors said investigators were able to trace him partly because he had not hidden his real internet address at one point in the operation.[5]

On April 30, 2024, a Finnish district court convicted him of aggravated data breach, more than 21,000 counts of attempted extortion, 20 counts of aggravated extortion and more than 9,500 counts of aggravated dissemination of information violating privacy. He was sentenced to 6 years and 3 months.[1][5] By victim count it is the largest criminal case in Finnish history.[6] He denied the charges throughout.[6]

What it cost

He was released in September 2025 while his appeal continued, because of the time he had already spent in custody.[2][6] In February 2026 the Helsinki Court of Appeal raised the sentence to 6 years and 11 months, and on July 13, 2026, Finland's Supreme Court refused to hear a further appeal, making it final. Police then issued a wanted notice, and his lawyer suggested he may be abroad.[6][7]

The company paid too. Finland's data protection authority fined Vastaamo €608,000 in December 2021, though by then it was already bankrupt.[2] Its former chief executive received a 3-month suspended sentence in 2023 over the handling of the data, but an appeals court acquitted him in December 2025.[2] The case also pushed Finland to let people change their national identity numbers, which many victims needed.[1]

The missing control

The missing control: access control on the sensitive database. The patient records needed strong, unique credentials on every account, especially the administrator one, plus encryption, limits on who and what could connect, and a log of who read the data.

Any one of those would have raised the cost of this attack. Together they would likely have stopped it: a password on the administrator account, encryption of the notes and a rule that the database only answers to the clinic's own application would have left a stolen login with little to take. Watching access would have caught a bulk copy in 2018, not 2 years later when patients started getting ransom emails.

What to do in your business

Watch the case
When a hacker emailed therapy patients directlyDrops 2026-11-08
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. AP via Spectrum News: Finnish hacker gets prison for accessing thousands of psychotherapy records and demanding ransoms
  2. Wikipedia: Vastaamo data breach
  3. BleepingComputer: Finnish psychotherapy clinic discloses data breach, victims extorted
  4. The Register: Finnish psychotherapy clinic ransom attack
  5. BankInfoSecurity: Finnish hacker Kivimaki found guilty in Vastaamo hack
  6. Yle: Kivimaki files Supreme Court appeal in Vastaamo case
  7. Kaleva: Supreme Court denies leave to appeal, Kivimaki sentence stands