The criminals demanded from the psychotherapy center Vastaamo 450,000 euros in exchange for stopping publishing the data. The release of patient data - including minors - ceased on Friday, sparking rumors about a possible payment. The information published so far includes the patient's personal data and the content of the therapy sessions.
The other crime here is why was such sensitive data being monolithically recorded and stored in the first place?
That it was being done so completely undermines the necessary trust a patient must have with their therapist.
Also, the server’s had a simple password-username pair and the patient data was stored in plaintext.