2 ms·
Additional context from HS: https://www.hs.fi/kotimaa/art-2000009931214.html https://www.hs.fi/kotimaa/art-2000009931214.html The suspect is accused of stealin
by terom 3y ago
Additional context from HS: https://www.hs.fi/kotimaa/art-2000009931214.html https://www.hs.fi/kotimaa/art-2000009931214.html
The suspect is accused of stealing tens of thousands of sensitive psychotherapy patient records from a MySQL server exposed to the public internet, using what I presume to be a weak MySQL (root) password.
The suspect is then accused of ransoming first the private healthcare provider, and then the individual patients (using the stolen email addresses). The ransomer went public and started leaking the patient records in batches of 100, before prematurely leaking the entire set by accident. The records contained what I believe included full detailed records from the individual psychotherapy sessions.
The company was aware of the breach, but did not report it before the attacker went public. There was, if I recall correctly, some kind of crypto locker compromise that brought their systems down, but those were only reported as some form of technical maintenance gone wrong.
Harder to find a source for it because the older articles are paywalled, but the IT employees responsible for the systems were not charged, instead the CEO was convincted of some form of criminal negligence. Plus financial fraud for selling the business without disclosing the earlier breach.