Finnish psychotherapy provider Vastaamo disclosed that its patient database had been stolen, and patients soon began receiving emails demanding bitcoin to stop their therapy notes being published. The case caused national shock in Finland.
What happened
- The database was first accessed in 2018, and security weaknesses persisted into 2019.
- Records of tens of thousands of patients, including therapy notes and national identity numbers, were exposed.
- Vastaamo’s chief executive was dismissed for concealing the breach from the board, and the company later went bankrupt.
- In 2024 a Finnish court convicted Aleksanteri Kivimäki over the extortion and sentenced him to more than six years in prison.
Why it mattered
The attack showed the human cost of breaches involving mental health data, with individual patients directly targeted for extortion. It also led to calls in Finland for stronger protection of national identity numbers and better support for victims of data breaches.
Lessons for organisations
Encrypt sensitive records, minimise what is stored, and escalate security incidents to the board promptly. Frameworks such as ISO/IEC 27001 help make these responsibilities clear. Make sure incident plans include support for affected individuals, not just technical recovery.
Source: CNN
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.