KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!





A large psychotherapy clinic in Finland is under heavy stress after a threat actor asked a ransom for a client database with confidential information stolen in a data breach that likely happened almost two years ago.
Thousands of patient records may be at risk as the private clinic is a nationwide practice with more than a dozen branches and other institutions contract its services.
Psychotherapy Center Vastaamo announced the incident last Wednesday, saying that the extortionist first contacted three of its employees in September, asking for 40 bitcoins (currently over $500,000) not to release stolen patient data.
The attacker threatened to publish patient data in an attempt to force the clinic into paying the ransom and kept their word. Since the public notice, they leaked at least 300 patient records on a site in the Tor anonymity network, according to a local source.
The matter escalated even further as the extortionist started to contact victims over email andย askedย for $240 in Bitcoin (EUR 200) to delete their records.
The messages have the subject line โAnswering Office Informationโ and contain the recipientโs personal information.
Also Read: How To Make A PDPC Complaint: With Its Importance And Impact
The threat actor may have been encouraged to do this after several individuals finding the leak site offered to pay to have their information removed from the stolen database. For them, the blackmailer set a price of 0.05 Bitcoin (about $650), Ilta Sanomat reported.
The same newspaper said that the attacker “writes very good English” and that they rely on privacy-oriented email services. Initially, they used Tutanota, then switched to Protonmail and Cock.li, the latter allowing registration and usage over Tor and similar privacy services.
In a press conference on Sunday, the Finnish National Bureau of Investigationย confirmed that the number of leaked patient records amounts to tens ofย thousands.ย Laura Halminenย ofย Helsinginย Sanomat was able to confirm that the blackmailer leaked at least 2,000 patient records.
As per her report, the extortionist uploaded for a brief time a 10GB file with Vastaamo patient information including names, social security numbers, postal and email addresses, phone numbers, and therapists’ notes on patient appointments.
Vastaamo has been publishing updates about the incident almost daily since the initial public disclosure. Before this, the clinic informed the Finnish Cyber โโSecurity Center, Valvira, and the Data Protection Commissioner.
Ethical hackers in Finland are also helping authorities, providing ย the policeย any digital breadcrumbs they find on the extortionist, such as messages, screenshots of sites, and metadata.
Technical aspects of the hack are being investigated by cybersecurity company Nixu, who found that the incident likely happened in November 2018.
โBased on the investigations, it seems probable that the data breach that led to the theft of the customer database took place in November 2018โ
–ย Vastaamo
This means that sensitive information of customers registered after the breach is not included in the leaks, Vastaamo clarifies in its notifications.
Also Read: Deemed Consent PDPA: How Do Businesses Comply?
It was not the only intrusion, though. In mid-March 2019, another breach occurred, and the CEO knew about it but decided to keep it a secret from the private clinicโs Board of Directors, authorities, and affected individuals.
Following this revelation, Vastaamo Board of Directors relieved Ville Tapio of his CEO position in the company.
It is not clear at this point in the investigation if the hackers stole the customer database but there is the possibility that the intruder viewed or copied the information.
The breach in March prompted steps that corrected the issues related to the protection of customer information, especially since Vastaamo was to be acquired by PTK Midco in May.
As part of the acquisition process, an external cybersecurity audit was commissioned in April-May 2019. It revealed no problems.
According to Vastaamoโs updates, Nixuโs investigation so far confirms that the clinicโs infrastructure did not have critical security vulnerabilities and did not suffer a cyberattack after March 2019.
PTK Midcon, owned by private equity firm Intera Partner, is the main shareholder of Vastaamo and started litigation on Monday about the acquisition process in May 2019.
Vastaamo is offering victims of the data breach support over the phone, advising on what to do if their private information has been leaked online.
Update [Oct 27, 2020]: Article updated with information fromย Laura Halminenย and herย report in Helsingin Sanomat.