Drooid Logo
Back to story perspectives

Full Breakdown

The Vastaamo Hack: A National Scandal in Finland

1/17/2026, 6:53:04 AM

Overview of the Incident

In October 2020, a significant data breach occurred at Vastaamo, a Finnish psychotherapy service, affecting approximately 33,000 patients. The breach involved the theft of sensitive patient records, including personal details and therapy notes, which were subsequently held for ransom by an unidentified hacker. The hacker demanded payment in bitcoin, threatening to publish the stolen information if the ransom was not met. This incident quickly escalated into Finland's largest-ever cybercrime scandal, prompting an emergency response from the government.

The Impact on Victims

Meri-Tuuli Auer, one of the affected patients, received a ransom email containing her personal information and details of her therapy sessions. The breach deeply affected her mental health, leading to anxiety and fear of public exposure. Auer had shared intimate details with her therapist, including struggles with depression and personal relationships, and the thought of this information being made public was devastating. She described the experience as a turning point, revealing her resilience in the face of trauma.

Investigation and Arrest

The investigation into the Vastaamo hack was complex, with Finnish police initially struggling to identify the perpetrator due to the vast amount of data involved. After two years of investigation, authorities named Julius Kivimäki, a known cybercriminal, as the primary suspect in October 2022. Kivimäki was arrested in France in February 2023 and extradited to Finland to face charges. The trial attracted significant public interest, with screenings held in cinemas to accommodate the 21,000 former patients who registered as plaintiffs.

Legal Proceedings and Sentencing

During the trial, Auer attended a public screening and noted Kivimäki's unremarkable appearance, reflecting on how easily he could blend into society. In July 2023, Kivimäki was found guilty of the charges and sentenced to six years and seven months in prison. Auer expressed a sense of validation from the court's acknowledgment of the victims' suffering, although she recognized that no sentence could fully compensate for the trauma experienced by those affected.

Criticism and Ongoing Concerns

Despite the conviction, Kivimäki continues to deny responsibility for the hack. The incident has raised broader concerns about data security and the protection of sensitive information in mental health services. The Vastaamo case has highlighted the vulnerabilities within digital health records and the potential consequences for patients when such data is compromised.

Conclusion

The Vastaamo hack serves as a cautionary tale about the importance of cybersecurity in healthcare. As victims like Meri-Tuuli Auer continue to navigate the aftermath of this breach, the case underscores the need for robust protections to safeguard personal information in an increasingly digital world.