Don’t do SECURITY. Do business SECURELY.

Hacked Finnish therapy provider’s patients face blackmail

Vastaamo, a Finnish psychotherapy provider, reveals a breach of patient records, and tens of thousands of patients are targeted with extortion.

Finnish psychotherapy provider Vastaamo disclosed that its patient database had been stolen, and patients soon began receiving emails demanding bitcoin to stop their therapy notes being published. The case caused national shock in Finland.

What happened

  • The database was first accessed in 2018, and security weaknesses persisted into 2019.
  • Records of tens of thousands of patients, including therapy notes and national identity numbers, were exposed.
  • Vastaamo’s chief executive was dismissed for concealing the breach from the board, and the company later went bankrupt.
  • In 2024 a Finnish court convicted Aleksanteri Kivimäki over the extortion and sentenced him to more than six years in prison.

Why it mattered

The attack showed the human cost of breaches involving mental health data, with individual patients directly targeted for extortion. It also led to calls in Finland for stronger protection of national identity numbers and better support for victims of data breaches.

Lessons for organisations

Encrypt sensitive records, minimise what is stored, and escalate security incidents to the board promptly. Frameworks such as ISO/IEC 27001 help make these responsibilities clear. Make sure incident plans include support for affected individuals, not just technical recovery.

Source: CNN

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights