The breach that turned therapy notes into a weapon

Most data breaches threaten your wallet. This one threatened something else: tens of thousands of Finns opened an email that quoted, word for word, what they had told their therapist. Then it demanded money, one patient at a time.

What actually happened

Vastaamo was Finland’s largest private psychotherapy provider, running roughly 25 clinics across the country and holding therapy notes for an estimated 33,000 patients. Prosecutors say Aleksanteri “Julius” Kivimaki breached Vastaamo’s patient database by exploiting an administrator account with no real password on a server left reachable from the open internet without firewall protection, and copied records that included patients’ names, addresses, and the actual written notes from their therapy sessions.

He first tried extorting the company itself, demanding 40 bitcoin (reported at roughly €400,000-450,000 at the time) to keep the database from being published. When Vastaamo did not pay in full, the attacker escalated to something far more personal: individually emailing an estimated 30,000 patients, quoting details from their own therapy notes, and demanding around €200 each in bitcoin, rising to about €500 if they didn’t pay within 24 hours, with a threat to publish the specific patient’s notes if they refused. Roughly 22,000-24,000 of those patients reported the extortion attempt to police. Some patients’ notes were published on the dark web.

Vastaamo’s business collapsed within months of the breach becoming public. Helsinki’s district court declared the company bankrupt on February 15, 2021, about four months after the extortion attempt went public in October 2020. Kivimaki was arrested near Paris in February 2023, extradited to Finland, and in April 2024 was convicted and sentenced to six years and three months in prison by a Finnish district court. That was not the final word. Finland’s Helsinki Court of Appeal increased the sentence to six years and eleven months in February 2026, and the Supreme Court refused to hear a further appeal in July 2026, making that sentence final. Kivimaki did not report to prison to begin serving it. As of this writing, he is the subject of a nationwide wanted notice and is believed to be abroad. (Whatever he thought “untraceable” meant, it didn’t survive contact with a patient prosecutor and a blockchain ledger, though evidently it’s survived contact with a Finnish prison cell.)

The artifact: not the stolen notes, the trail from database to bitcoin wallet to defendant

The therapy notes were the headline, and the human damage was real, but they weren’t what convicted Kivimaki. What built the case was a chain of technical attribution spanning years and jurisdictions: server access logs from the breach itself, the infrastructure used to send tens of thousands of individualized extortion emails, and cryptocurrency transaction tracing linking bitcoin wallets that received ransom payments back to wallets and exchange accounts investigators could tie to Kivimaki. (Real forensic work looks less like a hacking montage and more like a very long, very patient spreadsheet.)

None of those links is self-explanatory on its own. A server log showing unauthorized access proves a breach happened, not who did it. A bitcoin address that received ransom payments proves money moved, not whose hands were on the keyboard that sent the demand. Investigators had to connect the technical infrastructure used to breach the database to the infrastructure used to send the mass-extortion emails, and connect both of those to cryptocurrency movements that eventually touched an identifiable account, before that chain became evidence a court would accept. (A useful reminder that “the wallet paid out” and “this specific person controlled the wallet” are two separate claims, and only one of them is usually easy.)

What a software expert witness actually tests in a breach-and-extortion case

This is exactly where a software expert witness does work a lawyer’s summary can’t: it doesn’t stop at “the database was accessed” or “the wallet received payment.” It tests whether the access logs are complete and internally consistent, whether the infrastructure used for the breach can actually be tied to the infrastructure used for the extortion campaign, and whether the cryptocurrency trail from ransom payment to a named individual survives scrutiny at every hop, not just the first and last one.

That means examining what the breached system actually logged, and for how long, before concluding what an attacker could or couldn’t have done. It means understanding that a mass-extortion email campaign leaves its own infrastructure fingerprint (sending servers, templating patterns, timing) separate from the original database breach, and testing whether the two are actually linked or merely alleged to be. And it means treating blockchain analysis as a probabilistic discipline with its own error margins, not a magic wand that proves identity on its own.

None of that is exotic. It’s patient, structured work: document each technical layer separately, state what each one actually proves, and show where independent layers converge rather than assuming one strong-looking link closes the whole case.

Why this matters beyond one clinic

Vastaamo is an extreme case because the data was uniquely intimate, but the underlying failure is ordinary: a database that should never have been reachable without strong access controls held records that could not be un-published once exposed. Any organization holding sensitive personal data, medical, legal, or financial, is one misconfigured server away from the same exposure, even without a sophisticated attacker.

For Israeli healthcare providers, legal practices, and the litigators who represent breach victims or defend organizations accused of inadequate security, the lesson isn’t really about one Finnish clinic. It’s that a breach-and-extortion dispute needs an expert who can speak to access logs, extortion infrastructure, and financial tracing as three separate technical questions, not one blended story.

The above is general information and not legal advice. Case facts are drawn from Finnish court reporting and contemporaneous news coverage listed in the accompanying claims ledger.