11 ms·
This was one nefarious operation by the hacker: - He hacked the patient files of a psychotherapy center Vastaamo. This included therapy notes for more than 22.
by pasiaj 4y ago
This was one nefarious operation by the hacker:
- He hacked the patient files of a psychotherapy center Vastaamo. This included therapy notes for more than 22.000 patients.
- First the hacker blackmailed the therapy center.
- Next he started blackmailing individual patients.
- Finally he released the files online revealing very private information on thousands of patients.
I can only imagine the horror felt by the people whose therapy notes were made public.
- jnsie 4y agoAbsolutely heinous
- tough 4y agoand exactly why a paranoid person like me might abstain from ever seeking counsel from a therapist. Not worth it
- threatofrain 4y agoI don’t know if it would work but you might ask the therapist to have in writing that they will never take records of your sessions except for the bare minimum required by accounting.
- Sakos 4y agoThis depends on where you live and what the facility is like, no? At least in Germany, patient records like therapy notes are only hard copy. I don't see why they should ever be digitalized and I'd never go to a therapist or a facility that did have notes in digital form. I'm not particularly paranoid either, I'm just aware of how common it is for companies to be hacked and how rarely they face any consequences for not sufficiently investing in IT security.
- Tycho 4y agoEven if something only exists as hard copy today, who knows if it will stay that way. Some new regulation might come along requiring practices to digitise all their records.
- carlosjobim 4y agoA much larger threat than any hacker is a future government using that data to go after people deemed unwanted. Or the current.
- fsckboy 4y ago>why a paranoid person like me might abstain from ever seeking counsel from a therapist one of the benefits of therapy that you are missing out on is learning that what you are ashamed of is much less important than that you feel all that shame toward yourself. everybody else has much they are ashamed of, it's not a big deal
- momeunier 4y agoI thought the problem with Vastaamo was that the CEO was in charge of the mysql database and he was basically a hobbyist that didn't care much for security. (yeah zero proper sources for that... my level of Finnish is terrible) And then Murphy's law kicked it. A vilain nabs the data for free and does his thing.
- deleted 4y ago[deleted]
- Hamuko 4y agoMySQL server was without any kind of firewall protection for about 1.5 years, and the root account had no password. https://www.iltalehti.fi/digiuutiset/a/69314f2e-bb1c-4ea0-8ad6-9a188e0668b5 https://www.iltalehti.fi/digiuutiset/a/69314f2e-bb1c-4ea0-8a...
- Sakos 4y agoThe guy should be in jail with the hacker. That's crazy.
- jacquesm 4y agoJails would not be large enough if everybody that exposed customer data would end up in jail with the hacker.
- Sakos 4y agoI think if it did start happening, CEOs and management types would start caring about IT security to avoid being put there.
- jacquesm 4y agoLiability for the whole software industry needs to be re-thought. The problem with jailing CEOs is that even if it would work the first couple of times the other possible effect would be that people would do even more to brush their fuckups under the carpet... The EU has got this right I think: massive fines in case of a breach to the point that the CEOs are starting to pay attention. That certainly isn't perfect but it is a step in the right direction. Healthcare is particularly vulnerable and I'm always surprised that people in HC seem to think that they aren't a target. This is a huge mistake imo, there is massive blackmail potential in healthcare data.
- to11mtm 4y ago> I can only imagine the horror felt by the people whose therapy notes were made public. I might be in the minority here, but frankly I'd be -happy- to actually be able to see a therapist's notes on me. At least in my region, one of the first things you sign before any therapy begins usually contains a paragraph that such notes are 'IP' of the therapist/provider and thus something you as a patient are never allowed to see.
- MidnightBullet 4y agoSounds like something that would break GDPR
- closewith 4y agoIn the EU, at least, you have a right to all information that a healthcare provider holds about you, so either an administrative request or data subject access request will get you that data for free, and without the possibility of it being used against you by third parties.
- retrac 4y agoThere is such a right where I live too, but there is an exception: when the release of that information is thought to be harmful to that individual. I can certainly imagine how allowing a paranoid person suffering from delusion, to read the unfiltered medical notes of their psychiatrist, could be quite harmful. I don't know how often this actually comes up; I read the report of the last psychiatrist I saw in its entirety. They always suggest you shouldn't. Probably right about that. "Subdued affect"? Ouch.
- Sharlin 4y agoWhy is “subdued affect” ouch? Just about anyone who’s depressed or just melancholic has a “subdued affect”.
- this_steve_j 4y agoThere appears to be an excluded middle scenario that you are in fact describing, wherein a patient would be happy to peer behind the curtain at the doctor’s notepad for their own session (but not everyone else’s). Fewer patients would be happy to see the doctor’s notes for all other patients including themselves. Fewer still would appreciate having everyone, including non-patients, see not only their notes but all of the other patients in that practice.
- closewith 4y agoDoes Finland have a legal doctrine that makes evidence inadmissible in court if it was illegally obtained? I wonder could law enforcement use admissions of criminal activity in the released notes as evidence against patients?
- vesinisa 4y agoThere is no blanket provision to make unlawfully obtained evidence inadmissible but the judge must still forbid using any document that was i.a. obtained through a "gross" violation of the person's legal rights. So in this specific case the evidence would probably be inadmissible.
- formerly_proven 4y agoMost likely these documents are protected from prosecutors in the same way they would be without the breach, because the breach does not alter the type of document.
- vesinisa 4y agoIt's not all black & white. In the ANOM case the FBI, through a Swiss cover company, sold criminals "super encrypted" mobile phones.[1] In reality, the phones were backdoored and all their messaging leaked to the FBI. This uncovered several criminal operations in Finland such as drug trafficking rings. The FBI shared this correspondence with the Finnish police. When the case came to court, the defendants' first action was of course asking the court to suppress all evidence from the FBI because it was obtained illegally, as the criminals obviously had an expectation to the privacy of their correspondence, which was illegally violated. The court actually ruled that the messages are only admissible if they pertain to crimes that carry a maximum penalty of at least four years in prison, which is the same threshold that allows the Finnish law enforcement to use wiretapping.[2] [1]: https://en.wikipedia.org/wiki/ANOM https://en.wikipedia.org/wiki/ANOM [2]: https://www.hs.fi/kotimaa/art-2000008761772.html https://www.hs.fi/kotimaa/art-2000008761772.html (paywalled & encrypted in Finnish)
- mikkohypponen 4y agoChapter from my book, about Case Vastaamo: https://ifitssmartitsvulnerable.com/s/vastaamo_excerpt.pdf https://ifitssmartitsvulnerable.com/s/vastaamo_excerpt.pdf
- jacquesm 4y agoSo, you get to add another set of paragraphs. Excellent writing by the way.
- moremetadata 4y agoAnd you seriously think the State hasnt done this for years, in plain sight, starting the day you born? You have a lot to learn.
- h0p3 4y agoSo, how concerned are you with government use, either directly or indirectly, of machine learning?
- capableweb 4y agoThat was truly horrible, despicable. But I personally relate more to the horror the hacker put himself through: > security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder > “It was a huge opsec [operational security] fail, because they had a lot of stuff in there — including the user’s private SSH folder, and a lot of known hosts that we could take a very good look at,” What a huge flop! I can recall feelings myself publishing things I shouldn't, but the entire home directory, including private keys and everything? I'd die of shame. Still, really terrible behavior from him, he deserves whatever punishment is coming for him.
- deleted 4y ago[deleted]
- iepathos 4y agoThought the same. Ransom Man aka Incompetence Man.
- throwawaylinux 4y agoNot the worst superpower to have, but it's up there.
- wyclif 4y agoHe doesn't even know how to make his Reddit comments private.
- bawolff 4y agoI wish we would stop calling these types of people hackers and just call them extortionists. The fact a computer was used to commit the crime really changes nothing about the crime. If he physically broke in we wouldn't call him a nortorious lockpicker.
- grugagag 4y agoHacker turned extortionist sounds like a better description of this guy.
- labrador 4y agoI think "cyber-criminal" is the term in common usage
- labster 4y agoYeah, but “cyber” is such a cringe prefix.
- mangamadaiyan 4y agoIt has impeccable pedigree, though: https://en.wikipedia.org/wiki/Cybernetics https://en.wikipedia.org/wiki/Cybernetics
- pyuser583 4y agoWasn’t cybernetics a borderline pseudoscience? I mean read Stanley Milgram’s “Obedience to Authority” (with the actors who pretended to be shocked). It was fascinating until he got to the theoretical implications. All cybernetic gobbledegook. I prefer thinking of the “helmsman” of Ancient Greece when I hear Cyber/Kuber.
- stavros 4y agoFun fact, the words "cybernetics" and "kubernetes" are different transliterations of basically the same word.
- pyuser583 4y agoSo were these files somehow scrubbed from the Internet? Or is peoples private info still out there? It seems the Internet does have a delete button. Has it been used again?
- jacquesm 4y agoNo, you can't get rid of those files, they were uploaded in their entirety to anonymous file sharing services. It's absolutely horrible, and the damage to these people's lives is huge. The degree of lack of empathy that you'd need to have to blackmail the customers of an institution like that is one I have trouble comprehending.
- agumonkey 4y agothat's one of the lowest target crowd i could ever think of.. really rotten creativity from this dude.
- neither_color 4y agoSometimes I understand hackers from developing countries(not Finland!) in bad circumstances who have a chip on their shoulder against corporations... but this is just as scummy as it gets. This is worse than getting into people's bank account IMO. Taking advantage of people who shared their deepest darkest secrets and vulnerabilities with a trusted authority is beyond cruel, it could trigger someone into self-harm or worse. These same hundreds of people will be afraid to open up to their psychologists again. I hope this psychopath is never allowed near a computer again.
- Slighted 4y agoThank you for stating the obvious that anyone in this thread would've known had they read the linked article for even just a minute.
- tomalpha 4y agoSuch a summary can be very helpful to disambiguate the subject matter and save me (and I’m guessing many other folks too) the time of reading every article to find out whether it’s interesting/relevant to me.
- helsinkiandrew 4y agoActually it was 33000 patients. 22000 have so far made statements to the police: https://yle.fi/a/3-12543823 https://yle.fi/a/3-12543823 The owner of the company tried to sell it a few months later without declaring the data breach to the new owners and has been forced to pay €8M compensation: https://yle.fi/a/3-12479562 https://yle.fi/a/3-12479562
- lostlogin 4y ago22,000 police statement were made?!
- helsinkiandrew 4y agoYes - these were probably done online, rather than involving a police station visit, the police have been soliciting for victims: https://poliisi.fi/en/instructions-to-victims-of-hacking https://poliisi.fi/en/instructions-to-victims-of-hacking
- x98asfd 4y agoI don't care what encryption we are using. Therapy notes should always be in paper and locked in therapist office. Medical info should have NEVER being digitized.
- sofixa 4y agoVehemently disagree. Stifling progress because of the risks involved isn't worth it, the risks need to be assessed, acknowledged and accounted for. Digitising medical info is brilliant and extremely useful for anyone involved. Handoff between practitioners is seamless, and no more of the redundant "are you allergic to anything? any priors? are you taking any meds?", because the practitioner knows everything they need to (e.g. your dentist doesn't need to have access to your therapy notes, but should probably know all meds you're taking and all previous dentistry work done on you, wherever and wherever that happened). It would also allow for country-wide anonymous statistical analysis. Oh, everyone taking pill X is also having Y? Is there a problem there? A lot of people getting operated for A used to do Z, C, so maybe we need a better educational campaign so people know the risks? The possibilities - life saving, medical system improving, etc. are enormous. It just needs to be handled with extreme care, because the risks are enormous. Security should be top notch, with strict access controls, anonymisation where needed, etc.
- Xylakant 4y agoYour parent made a much narrower point than you’re debating: you argue in favor of digitizing general medical info and your parent made the point that therapy notes should be paper-only and locked. The risk/reward tradeoff is different for those than allergies, general medication etc. The information contained is much more sensitive and at the same time they’re much less likely to be passed off between therapists unfiltered and unredacted. Both, digitizing general medical info and keeping specific bits in analog form for safety and security reasons are not mutually exclusive.
- sofixa 4y agoParent said: > Medical info should have NEVER being digitized. Which i assumed to be talking about all medical info. > The information contained is much more sensitive and at the same time they’re much less likely to be passed off between therapists unfiltered and unredacted. Why not?