The Vastaamo Hack: How a Finnish Therapy Data Breach Became a National Trauma
In 2020, Finland was rocked by a devastating cyberattack against Vastaamo, a popular psychotherapy provider. The hacker, using the alias ‘ransom_man,’ stole sensitive therapy records from 33,000 patients and demanded ransom payments in bitcoin. When the company refused to pay, the attacker began leaking therapy notes—documents containing people’s most personal confessions—on the dark web, exposing politicians, police officers, and even children. Victims were extorted directly, some paying in desperation, while others suffered immense psychological distress. At least two people are believed to have taken their own lives after their private data was exposed.
The Vastaamo breach revealed shocking lapses in data security. Investigators found that the company’s database lacked a firewall and even a password, making it easy to access. Cybersecurity expert and former police detective Antti Kurittu traced the hacker’s patterns and style, recognizing the work of Finnish hacker Aleksanteri (Julius) Kivimäki, also known as ‘zeekill,’ notorious for his involvement in earlier international cybercrimes, including attacks on Sony and Lizard Squad activities. Kivimäki had a long history of harassment, extortion, and online chaos, showing little remorse. For Finnish society—famed for its trust in digital systems and mental health transparency—the Vastaamo hack was more than a crime; it was a national trauma that exposed the dark side of digitalization and the vulnerability of private therapy data.
