HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Finland Issues Wanted Notice for Hacker Behind Vastaamo Psychotherapy Data Breach

A Finnish court upheld a seven‑year sentence for a hacker who stole and published ~33 000 psychotherapy records, highlighting the need for robust privacy controls and audit‑ready evidence under SOC 2. Verisq’s CookiePLUS privacy capability can help map consent and demonstrate compliance.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Finland Issues Wanted Notice for Hacker Behind Vastaamo Psychotherapy Data Breach

What Happened — Finnish authorities have issued a wanted notice for convicted hacker Aleksanteri Kivimäki after the Supreme Court declined to hear his appeal. Kivimäki was sentenced for hacking the psychotherapy provider Vastaamo, stealing a database of ~33 000 patients, and extorting both the company and its clients. The stolen records were later published online, exposing highly sensitive mental‑health notes.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates the catastrophic impact of a data‑exposure breach on privacy obligations (GDPR, CCPA) and the need for documented consent, data‑minimisation, and breach‑response controls.
  • Continuous evidence of privacy‑policy enforcement and DSAR readiness is a core SOC 2 CC5 (Privacy) requirement; gaps become audit findings after a breach of this magnitude.
  • Verisq’s CookiePLUS privacy capability helps organisations map consent flows, maintain audit‑ready records, and demonstrate compliance with privacy‑focused controls.

Who Is Affected – Health‑care & mental‑health providers, especially those storing psychotherapy notes and other highly sensitive personal data.

Recommended Actions

  • Review and update privacy policies, consent mechanisms, and data‑retention schedules to align with SOC 2 CC5.
  • Conduct a privacy‑impact assessment (PIA) on all patient‑record systems and document remediation steps as audit evidence.
  • Test breach‑notification procedures and DSAR workflows; ensure logs and evidence are retained for the statutory period.

Technical Notes – The breach stemmed from a targeted intrusion into Vastaamo’s internal systems (exact exploit not disclosed). Stolen data included therapy notes, personal identifiers, and contact information. The attacker later published the data on underground forums. Source: The Record

📰 Original Source
https://therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →