
The Vastaamo case is often remembered as the story of Julius Kivimäki, the Finnish hacker now known as Aleksanteri Kivimäki. That framing is too small.
The real lesson is colder: when mental health records are stored badly, logged badly, and disclosed late, the data itself becomes the weapon. Encryption was not the pressure point. Public exposure was.
TL;DR
- Finland’s Supreme Court refused Kivimäki leave to appeal on July 13, 2026, leaving Helsinki Court of Appeal’s six-year-and-eleven-month sentence final.
- Finnish police and courts tied the Vastaamo case to a breach of roughly 33,000 psychotherapy patients’ records and mass extortion against victims.
- Yle reported on July 13, 2026 that police had issued a wanted notice for Kivimäki after the Criminal Sanctions Agency sought assistance in returning him to prison; his lawyer did not know his exact location and believed he was abroad.
- The technical root of the Vastaamo failure was not exotic: exposed database access, weak authentication, insufficient firewalling, poor logging, and delayed breach notification.
- Healthcare, therapy, legal, HR, and school systems should treat sensitive notes as extortion-grade data, not ordinary business records.
Where the Case Stands
Kivimäki was convicted in the Vastaamo case by the Western Uusimaa District Court on April 30, 2024 and sentenced to six years and three months in prison. The Helsinki Court of Appeal later increased the sentence on February 26, 2026 to six years and eleven months.
On July 13, 2026, Finland’s Supreme Court declined to grant leave to appeal. That made the Court of Appeal judgment final. The Supreme Court’s public notice identifies the convictions as aggravated data breach, twenty counts of aggravated extortion, numerous attempted aggravated extortions, and aggravated dissemination of information violating personal privacy.
Yle reported the same day that police issued a nationwide wanted notice at the request of Finland’s Criminal Sanctions Agency. According to that reporting, Kivimäki was to be arrested if found and taken to prison to serve the remaining sentence. His lawyer told Yle he did not know Kivimäki’s exact location and had a strong impression that he was not in Finland. Because this is an active enforcement situation, use dated wording: that was the public status reported in July 2026, not a substitute for a live police record.
Kivimäki has denied guilt during the legal process. That matters historically, but the criminal judgment is now final after the Supreme Court refused leave to appeal.
The Breach Was Personal by Design
Vastaamo was a psychotherapy provider. Its database did not just contain emails and billing addresses. It contained therapy records, diagnoses, identity data, and notes from sessions where patients had reason to expect confidentiality.
Finnish police said the case involved more than 30,000 customers’ sensitive information. Later court and media reporting commonly put the exposed patient database at about 33,000 people. After Vastaamo was extorted, individual patients were also targeted with ransom demands and threats to publish their private records.
That is the operational shift defenders should study. The attacker did not need to encrypt hospital workstations or disable care delivery to create leverage. The leverage already existed in the files.
For victims, the breach was not abstract. Password rotation does not repair a leaked therapy note. Credit monitoring does not undo public exposure of trauma, family history, substance use, or psychiatric treatment. This is why high-sensitivity systems need stronger controls than ordinary customer databases.
The Security Failure Was Boring, Which Makes It Worse
The Finnish Data Protection Ombudsman’s 2021 enforcement summary is blunt. Its investigation found that Vastaamo had not followed basic safe maintenance practices for the patient information system.
The most likely cause of the leak was an unprotected MySQL database port. The database root account had no password, remote access was allowed from any IP address, and the patient database server had been exposed to the internet without firewall protection for a long period between November 2017 and March 2019.
The same investigation also found that insufficient logs and documentation made it impossible to establish the exact breach timing, attacker network addresses, or methods with certainty. That is a second incident inside the first one: not only was the data exposed, the organization could not reliably reconstruct what happened.
There was also a reporting failure. Vastaamo notified the Data Protection Ombudsman in September 2020, but the authority found that the company should have reported earlier after becoming aware in March 2019 that patient data may have been compromised.
None of this requires advanced exploit development. It requires a database reachable from the internet, weak or missing authentication, and a governance process that failed to treat patient records as catastrophic-risk data.
A Practical Attack Path
The Vastaamo pattern can be reduced to a chain defenders can test against their own environment:
- A sensitive database is reachable from outside its intended trust boundary.
- Authentication or network filtering is weak enough for unauthorized access.
- The attacker copies the database.
- Logging is insufficient, so the organization cannot quickly prove scope.
- The attacker returns later with ransom demands.
- When the organization does not pay, victims are contacted directly.
- The incident becomes a privacy, clinical trust, legal, and public-safety crisis.
The uncomfortable part is step four. If you cannot prove what was accessed, when, from where, and by whom, you are negotiating facts while the attacker is weaponizing certainty.
Detection and Hardening for Sensitive Records
Healthcare and mental health providers should start with the assumption that their highest-risk data is useful for extortion even when no system is encrypted.
Database exposure
- Block database ports at the network edge. MySQL, PostgreSQL, MSSQL, MongoDB, Redis, and Elasticsearch should not be internet-reachable by accident.
- Require private network paths, VPN, bastion hosts, or identity-aware access for administration.
- Alert on any database service listening on public interfaces.
Authentication
- Remove passwordless administrative accounts.
- Restrict administrative logins by source network and role.
- Use separate accounts for application access, administration, backup, and analytics.
Logging
- Retain database authentication logs, query metadata, administrative access logs, firewall logs, and server audit trails long enough to investigate delayed discovery.
- Forward logs to a system the application administrator cannot silently alter.
- Test whether responders can answer: who accessed this record set, from where, and how much data moved?
Data minimization
- Do not store therapy notes, HR records, legal memos, or child welfare files in the same operational pattern as normal account data.
- Encrypt sensitive fields where practical, but do not treat encryption as a replacement for access control and monitoring.
- Separate identity data from clinical or case notes when business workflows allow it.
Response
- Have a breach notification playbook before the incident.
- Prepare victim support, identity-protection guidance, law-enforcement contacts, regulator notification steps, and public communications templates.
- Practice the direct-extortion scenario: attacker contacts customers, patients, employees, or students before the organization has finished forensics.
What Security Teams Should Take From Kivimäki’s Disappearance
The wanted-notice part of the story is legally interesting: after a final prison sentence, the convicted hacker was not simply sitting inside the system waiting for paperwork to finish. Public reporting placed him outside Finland or at least outside the reach of Finnish authorities, and his exact location was not known to his own lawyer.
Kivimäki had already been internationally wanted before his February 2023 arrest in France. Yle reported in July 2026 that he was again wanted after the Supreme Court refused leave to appeal and authorities sought to return him to prison. That history shows how long cybercrime cases can remain operationally unresolved even after attribution, arrest, trial, appeal, sentencing, and a final judgment.
If a reader has current, concrete information about the location of a wanted person, the right path is to report it to law enforcement through official channels. Do not approach the person, attempt amateur tracking, or publish supposed sightings online. Bad public tips can harm bystanders, compromise an investigation, and create fresh privacy damage around a case already defined by it.
For defenders, that means evidence must survive years.
Preserve logs. Preserve images. Preserve chain of custody. Keep incident notes clear enough that they still make sense when prosecutors, regulators, victims, insurers, and civil courts ask questions much later. The Vastaamo case moved from intrusion to extortion to bankruptcy to criminal prosecution to appeals over nearly eight years. Your retention plan should not assume every important question arrives within thirty days.
The Bigger Lesson
Vastaamo was an early warning for the extortion model now common across ransomware and data-theft crews: steal the data, skip the encryption, and threaten exposure.
What made it especially cruel was the target set. Patient records are not replaceable credentials. They are life records. Once copied and published, they cannot be rotated.
The technical lesson is basic because the human consequence is not. Sensitive systems need boring controls done well: no exposed databases, no passwordless admin access, no missing logs, no delayed reporting, and no uncertainty about who owns breach response.
If your organization holds records people would pay to keep private, attackers already understand their value. Your architecture should show that you do too.
Related Posts
- Ransomware Doesn’t Need to Encrypt Anymore - And That’s the Point - why data exposure has become enough leverage without encryption.
- Your Data on the Dark Web: How to Find It Without Ever Opening Tor - practical guidance for people worried about leaked personal data.
- Rapid Compromise Triage: Linux and Windows First Hour Checklist - what to preserve when an incident may become a legal matter.
- MDR: What It Is, What It Catches, and When You Actually Need It - monitoring and response capacity for teams without a full SOC.
Sources
- Korkein oikeus - Korkein oikeus hylkäsi valituslupahakemuksen Vastaamon tietomurtoa ja sitä seuranneita kiristysrikoksia koskeneessa asiassa
- Tuomioistuimet.fi - Vastaamo-kokonaisuus hovioikeuden käsiteltäväksi
- Poliisi - Vastaamo-tietomurron esitutkinta on valmistunut
- Finnish Government - Administrative fine imposed on psychotherapy centre Vastaamo for data protection violations
- Yle News - Police issue wanted notice for Vastaamo hacker Aleksanteri Kivimäki
- Yle News - French police arrest Finnish psychotherapy centre hacking, extortion suspect