The criminals demanded from the psychotherapy center Vastaamo 450,000 euros in exchange for stopping publishing the data. The release of patient data - including minors - ceased on Friday, sparking rumors about a possible payment. The information published so far includes the patient’s personal data and the content of the therapy sessions.

More context to the previous article I posted.


The other crime here is why was such sensitive data being monolithically recorded and stored in the first place?

That it was being done so completely undermines the necessary trust a patient must have with their therapist.


Also, the server’s had a simple password-username pair and the patient data was stored in plaintext.

