august

Vastaamo, 2018-2025

The Demands to Patients

On Saturday, October 24, 2020, thousands of people across Finland received the same extortion demand by email. It addressed them by name. It contained their personal identity code — the Finnish national identifier used for banking, employment, and medical care. And it explained, in businesslike terms, that the sender possessed the notes their psychotherapist had written about them: the sessions, the diagnoses, the things they had said out loud exactly once, in a quiet room, to a person bound to secrecy. The price of keeping those notes off the internet was 200 euros in bitcoin, payable within twenty-four hours. After that the price rose to 500. After that, publication.

The recipients were patients — current and former — of Vastaamo, Finland's largest private psychotherapy chain. Some had been in treatment for depression or panic disorder. Some had disclosed abuse, addiction, infidelity, suicidal thinking. Some had been children when the notes were written. Roughly 30,000 of them received the demand. The data was already gone; it had been gone for two years.

Extortion of hospitals and health companies was by 2020 a mature criminal industry, with its own economics and etiquette, chronicled elsewhere in this book from its invention at a Los Angeles hospital to its industrialization against entire national systems. But the demand had always been aimed at the institution. The institution had lawyers, insurers, incident-response retainers, a board to absorb the decision. The demands that arrived in Finnish inboxes that Saturday skipped the institution and put the ransom note in front of the patient directly.

The Psychotherapy Chain

Ville Tapio founded Vastaamo in 2008, in his twenties, and built it into the largest private psychotherapy provider in Finland — roughly two dozen clinics, hundreds of therapists, and a low-threshold model that let patients get appointments in weeks rather than the months common in the public system. Finland, like everywhere, had far more demand for mental health care than supply, and Vastaamo grew by meeting it. Much of its work was publicly subsidized or delivered under contract to the public sector; it was woven into the country's health system, not an alternative to it.

Tapio was not only the chief executive. He was, in the company's early years, its programmer. Vastaamo ran on a patient-record system built in-house, with Tapio himself among its authors — a common arrangement in a young company where the founder codes. Into that homegrown database went everything the business generated: patient identities and contact details, personal identity codes, appointment histories, and the therapists' session notes, accumulating year over year, for tens of thousands of people. Nothing was routinely purged. Records of patients who had left treatment years earlier sat beside those of active ones.

By every later account, the company's security remained at the level of its startup years. There was no dedicated security function comparable to what a bank holding equivalent-value secrets would consider minimal. Neither patients nor therapists could see the gap between what the database contained and what protected it.

The Intrusions and the Concealment

The patient database sat on a server reachable from the open internet, and the database's root account — the all-powerful administrative login — was not protected by a password. The court that later examined the company's conduct treated this as the absence of the most basic safeguard the technology offers. Anyone who found the server could take everything, and at least one person did.

The intrusions came in November 2018 and again in March 2019. The second one did not pass unnoticed inside the company: investigators concluded that Vastaamo's leadership became aware of a breach and told no one — not the data protection authority, to which European law required a report within seventy-two hours; not the patients whose files were exposed; and not the investment firm, Intera Partners, that bought a majority stake in the company in May 2019. The buyer would later pursue the sellers over that silence. For a year and a half after the second intrusion, the company carried on, its patients confiding in its therapists, its therapists typing notes into a system that had already been emptied.

For eighteen months, the roughly 33,000 people whose records had been taken — some 30,000 of whom would eventually receive demands — had no way to take even the small protective steps available to them. The only people who knew the data was loose were the company's leadership and the thief.

The Extortion Campaign

The first demand reached the company in late September 2020. An extortionist writing under the handle "ransom_man" wanted roughly 40 bitcoin — about 450,000 euros at the time — to withhold the stolen database. Vastaamo did not pay; it went to the police, and on October 21 it disclosed the breach publicly.

The pressure campaign began at once. On a Finnish-language Tor forum called Torilauta, ransom_man started publishing patient records in daily batches of a hundred — names, identity codes, and therapy notes, posted where anyone with the Tor Browser could read them. The extortionist then posted a compressed archive of nearly eleven gigabytes containing what appeared to be the entire patient database. The file was taken down quickly, but copies had already been made, and analysts who examined it found, alongside the stolen records and apparently swept up by mistake, a copy of the attacker's own home directory from his own computer.

When the company still refused to pay, ransom_man turned to the patients. Over the following days, the individual demands went out by the tens of thousands: 200 euros within twenty-four hours, 500 thereafter, publication after that. Finnish police urged recipients not to pay, to preserve the emails, and to file reports. The overwhelming majority did not pay; the court would later find that only about twenty people did.

Within days of the public announcement, Vastaamo's board fired Ville Tapio, stating that leadership had known of the earlier breach and kept it from them.

The National Response

Finland is small, digitized, and high-trust, a country where the personal identity code opens most doors of daily life and where roughly one person in every hundred and seventy was now a victim of a single crime. The response was national in a way few data breaches anywhere have ever been. The government convened an emergency session that weekend. Crisis helplines were reinforced and reported surges in contacts; churches and victim-support organizations opened their doors to people who had learned that the most sensitive documents about them ever written were in criminal hands. More than 20,000 victims filed police reports, making Vastaamo the largest criminal case in Finnish history measured by the number of complainants.

The state also did something almost without precedent in response to a private company's breach: it moved to change the law of identity itself. The personal identity code had been effectively permanent, changeable only in extreme circumstances, on the theory that a stable identifier is the foundation of an orderly digital state. After Vastaamo, the government fast-tracked work to allow victims of serious data breaches to be issued new codes, an admission, written into legislation, that the country's foundational identifier had become an instrument of harm for tens of thousands of its citizens.

The harm itself resists the vocabulary of the field. There were no canceled surgeries, no ambulance diversions, no downed systems; every Vastaamo clinic could see patients throughout. The crime attacked the precondition of the care rather than its delivery. Therapy depends on the belief that the room is sealed; the notes existed because patients had trusted that belief, and the breach converted every act of trust retroactively into exposure. In the months that followed, Finnish media reported deaths by suicide among the victims. No court or investigation made a formal causal finding, and the reports should be handled with the care they demand. The country did not need a finding to understand what had been put at stake.

The Bankruptcy and the Tapio Prosecution

The company died quickly. Its value collapsed with its disclosure, its patients scattered, and in February 2021 Vastaamo entered bankruptcy, its clinical operations sold off to a competitor. Later that year, Finland's data protection authority imposed a fine of 608,000 euros under the GDPR for the company's failures, including the unreported breach. The fine was correct in every particular and almost entirely symbolic: it landed on a bankrupt estate, joining a queue of creditors that included the victims themselves, whose compensation claims were now claims against a corpse.

The personal reckoning was more consequential, and less durable. In April 2023, the Helsinki District Court convicted Ville Tapio of a data protection offense for the company's failure to protect its patients' data, and handed him a three-month suspended sentence. Corporate security failures are ordinarily punished, when they are punished at all, with fines paid by shareholders and insurers; a criminal conviction of a chief executive, personally, for the state of his company's data protection was one of the rarest outcomes in the field, and executives who had absorbed decades of breaches as a cost of doing business took note. Then the precedent came apart. Both sides appealed, and in December 2025 the Helsinki Court of Appeal dismissed all charges, ruling that neither the GDPR nor the Finnish healthcare legislation in force at the time had required patient data to be encrypted or pseudonymized. What Vastaamo finally established was narrower than the district court's verdict had suggested: an executive can be prosecuted, personally, for his company's security failures, and can also walk free if the law never spelled out the safeguard he failed to provide.

Aleksanteri Kivimäki

The extortionist's identity emerged from his own archive. The home directory swept into the leaked dump gave investigators a starting point, and the bitcoin trail gave them another; in October 2022, Finland's National Bureau of Investigation named its suspect and issued a European arrest warrant. The name was one the country's police already knew well.

Aleksanteri Kivimäki, who had changed his first name from Julius, was an alumnus of Lizard Squad, the attention-seeking crew behind the Christmas 2014 attacks that knocked out Xbox Live and the PlayStation Network. In 2015, at seventeen, he had been convicted in Finland of 50,700 counts of computer-related offenses and, as a juvenile, received a suspended sentence: no prison, a fact that drew international incredulity at the time and acquired a much darker cast in retrospect. The teenager the system had declined to incarcerate was, prosecutors alleged, the adult behind ransom_man.

By the time he was named, Kivimäki was gone. He was found in February 2023 in Courbevoie, outside Paris, when French police responding to a report of a domestic disturbance encountered a man carrying identity papers that did not survive scrutiny; a fingerprint check matched the fugitive on the European warrant. He was extradited to Finland, where the trial, conducted under extraordinary arrangements to accommodate thousands of injured parties, ended in April 2024 with his conviction on charges including an aggravated data breach, aggravated extortion, tens of thousands of counts of attempted extortion, and the aggravated dissemination of information violating personal privacy. The Western Uusimaa District Court sentenced him to six years and three months in prison. He denied the charges throughout and appealed, and in September 2025 he was released from custody while the appeal was heard. The appeal made his position worse: in February 2026, the Helsinki Court of Appeal upheld the guilty findings and lengthened the sentence to six years and eleven months, one month below the statutory maximum. It is one of the heaviest cybercrime sentences in Finnish history — measured against 33,000 victims, still a light one.

Lessons

Vastaamo is small next to the breaches that fill the rest of this book. It took down no systems and left nothing to rebuild. It endures in the field's memory as the purest case study in what health data actually is, and what its loss actually does.

Sensitivity is set by content, not by record count. The opening chapter asked why a claims clearinghouse held enough detail on 190 million people to make a census-scale breach possible. Vastaamo asks the sharper version of the same question at one ten-thousandth the scale: why did verbatim psychotherapy notes sit in one internet-facing database, unencrypted, indefinitely? A stolen credit card is replaced; a stolen identity code, after Finland's reform, can be reissued; a stolen confession is unrecoverable forever. Minimization and retention limits are the control that keeps working after every other one has failed. The notes that were never stored, or were deleted when treatment ended, or were kept off any connected system, were the only notes ransom_man did not take.

When an institution refuses to pay, a criminal holding sufficiently intimate data can route around it and extort the people in the files, one by one. That is what Vastaamo established, and the precedent traveled: two years later, when an Australian insurer refused a ransom and its customers' most sensitive records were published in retaliation, the logic was recognizably Vastaamo's, a story that belongs to the chapter on Medibank. Every organization that holds intimate data has to assume its breach-response decisions will be inherited, involuntarily, by every person in its database — and that "we don't negotiate" is a policy whose costs may land at 30,000 kitchen tables.

Vastaamo's original sin was an unprotected database. Its unforgivable one was the eighteen months of silence after leadership learned of the breach. Disclosure would have been painful but survivable, and it would have protected the patients; concealment destroyed the company, exposed them twice over, and turned a negligence story into a fraud-adjacent one. Tapio's prosecution put a chief executive in a criminal dock, personally, for presiding over — and for hiding — a security failure. Though the conviction did not survive appeal, the years he spent as a defendant are now part of the calculus for anyone tempted to keep a breach quiet. The breach is an event; the cover-up is a choice, and the law increasingly treats it that way.

Fines cannot reach a company that no longer exists. The 608,000-euro GDPR penalty against Vastaamo's bankrupt estate collected almost nothing and deterred no one who was not already deterred. When a catastrophic breach kills the company that caused it, corporate fines arrive at the funeral. Deterrence for the worst cases has to attach to people — in this story it ultimately reached the extortionist but not, after the appeal, the executive — or operate before the fact, through the kind of inspection and enforcement that might have found an internet-facing database with no root password while it still mattered.

The case against Kivimäki began with his own home directory, accidentally shipped inside his own leak, and was finished by financial tracing. That is the ordinary anatomy of cybercrime attribution: patient forensic work waiting on a lapse in operational discipline. It argues for preserving and examining everything an extortionist publishes — the leak is also evidence — against the assumption that anonymity networks make such criminals unfindable. It took Finland's police two years to name him and four to convict him. Slow, in this case, was not the same as never.

Catastrophic data pools in small companies. Vastaamo held nation-scale secrets on a startup's security budget, and it is not unusual in that. Mental health providers, fertility clinics, addiction services, genetic-testing firms: the organizations holding the most damaging data per record are disproportionately small, young, and lightly regulated in practice, whatever the law says on paper. Health systems that contract out care contract out custody of their patients' inner lives. Security diligence has to follow the data down the subcontracting chain, to the smallest firm in it.

The confidentiality of the consulting room is older than the computer by a century, and older than that by millennia if one counts the confessional. Patients say the unsayable because a professional promises it will stay in the room, and every layer of technology added since — the typed note, the database, the internet-facing server — has stretched that promise thinner without anyone renegotiating its terms. Vastaamo is what the promise's failure looks like at full scale, distributed by email, priced at 200 euros a person. </content>