1. October 2020: the email 30,000 people could not unsee
For most of them it arrived at night. A short message, in Finnish, addressed by name. It said: we have your psychotherapy notes. Pay 200 euros in Bitcoin within 24 hours or it becomes 500, and after that we publish. Attached, as proof, were their own words - the things people say to a therapist and to no one else.
The source was Vastaamo, a private psychotherapy provider founded in Finland in 2008 that had grown into one of the country's largest, running dozens of clinics under public-health contracts. Attackers had been inside its systems since November 2018, with a second intrusion in March 2019. The patient database "was not encrypted and anonymized," and the "system root did not have a defined password." The most sensitive records a health system can hold were, in effect, sitting in an unlocked room.
When it became public on 21 October 2020, the scale was almost incomprehensible:
36,000 - patients exposed (plus 400 staff)
~30,000 - individual extortion emails sent
EUR 450,000 (40 BTC) - company ransom demanded
EUR 200 -> EUR 500 - per-patient demand, escalating in 24h
300+ - session notes published on Tor as proof
EUR 608,000 - regulator fine to Vastaamo
6 years 11 months - hacker's sentence on appeal, February 2026
Acquitted - the CEO's criminal liability, December 2025
The attacker had first tried to extort the company - 40 bitcoin, about 450,000 euros - and when that failed, turned the ransom on the patients one by one. To prove it was real, session notes of at least 300 people were dumped on Tor: notes describing suicide attempts, affairs, abuse, intrusive thoughts. Attached to real names.
The fallout set records. Vastaamo was declared bankrupt in February 2021. Finland's data-protection authority fined it 608,000 euros. The perpetrator, Aleksanteri Kivimaki, was convicted in April 2024 of aggravated computer break-in, 9,231 counts of disseminating private information, and over 20,000 counts of attempted aggravated extortion; on appeal in February 2026 his sentence was raised to 6 years 11 months - one month short of the legal maximum. It remains the largest criminal case in Finnish history by victim count.
And here is the detail that should unsettle anyone building in this space: the CEO who presided over that unencrypted database, Ville Tapio, was given a three-month suspended sentence in 2023 - and then, in December 2025, acquitted of all charges by the Helsinki Court of Appeal, which found that neither the GDPR nor Finnish healthcare law had clearly required encryption or pseudonymisation at the relevant time. The single worst mental-health data catastrophe in European history produced one jailed hacker and zero criminally liable operators.
The lesson Vastaamo burned into the industry: a mental-health data breach is not a fraud event. It is mass targeted extortion of the most vulnerable people in society, and the harm comes from a single thing - the linkage of a real identity to intimate content. A stolen credit card is replaceable. "I was abused at seven," attached to your name, is not.
2. The half of the lesson nobody finished
After Vastaamo, everyone hardened storage. Encrypt at rest. Pseudonymise. End-to-end encryption so a stolen database is, in the phrase, scrambled eggs. All correct. All necessary.
But Vastaamo only ever answered one question: how do we stop someone breaking IN to steal the notes?
The online-therapy boom quietly created a second one, and almost no one is asking it: how does the client know the person they are pouring their heart out to is who they claim to be - or qualified at all?
Every gain from encryption assumes the therapist on the other end is legitimate. Encryption protects the conversation in transit and at rest. It says nothing about who is sitting at the far end of it. You can build a perfectly sealed vault and still hand the key to a stranger at the door.
3. "How is it legal for anyone to call himself a therapist?"
On paper, it is not. In Latvia the title "psihologs" is legally protected: under the Psihologu likums a person may perform paid psychological work only with an accredited master's degree, entry in the state Register of Psychologists, and a field certificate. "Psihoterapeits" is protected even more tightly - it is a medical specialty, restricted to registered physicians. The register is public and free to search at viis.gov.lv. Anyone can verify any practitioner in seconds.
So why does the protection evaporate in practice? Three gaps, and online platforms live in all three:
- The duty is on the person, not the platform. The law obliges the individual to be registered. No statute forces a marketplace to check that they are. A platform can list fifty "psychologists" and verify none, and break no psychologist-law rule by doing so.
- Enforcement has no teeth at the point of sale. The psychologist law has no penalty chapter; enforcement is complaint-driven and after-the-fact. Nobody is checking at signup. The wrong is only discovered once someone has already been harmed and complains.
- The operator is often foreign. When the platform is run cross-border by an entity in another country (and the software licensed from a third), it sits in a jurisdictional seam where no single regulator is watching the front desk.
The result is a title that is protected in the statute book and unprotected in the product. The one artefact that actually proves lawfulness - the register number - is public, free, and simply not shown. Verification is not impossible or expensive. It is declined.
And recall Tapio's acquittal: the law is chronically a step behind the harm. If it could not cleanly hold the operator of an unencrypted database of 36,000 patients criminally responsible, it will be even slower to catch a platform that let an unqualified stranger take paid sessions. Waiting for the law to close this gap is not a plan.
4. The front door: when the impostor is the specialist
This is the scenario the industry does not want to picture, so let us picture it precisely. A platform that stores no credentials and shows first-name-only profiles has not merely failed to prevent a future breach. It has built a channel that manufactures the raw material of one - and left the door to it unlocked. Three failure modes, escalating:
The unqualified. A self-styled coach with no clinical training takes on a suicidal client, a trauma survivor, an eating-disorder case. No supervision. No malpractice insurance to sue. And if the crisis instructions on the platform point to the wrong country's emergency number, a person in acute danger is told to call a line that does not answer. The harm here is not theft; it is a vulnerable human being mishandled by someone with no business handling them, and no accountable party when it goes wrong.
The impersonator. Someone lists themselves under a real registered psychologist's first name and a stock photo. Because the platform shows no registration number and performs no identity check, the client has nothing to verify against. The name matches. The photo looks right. There is no way to tell the listing apart from the genuine clinician it copies.
The predator. This is the one that should end the debate. Vastaamo required an attacker to breach a database to obtain intimate disclosures. An impersonated therapist is handed them voluntarily, in real time, wrapped in the victim's complete trust - no intrusion, no encryption to defeat, no crime that trips an alarm. The victim self-selects as vulnerable simply by being there, and then narrates, on request, the exact identity-to-content dossier that made Vastaamo catastrophic. From that seat a bad actor can groom, manipulate, extort, run financial fraud through fake "treatment packages" and card capture, or just quietly harvest the material for later. It is Vastaamo without the hack - and the platform's own design is what seats the attacker in the chair.
Put plainly: Vastaamo was a failure of the walls. The verification gap is a failure of the door. And a door left open does not need a burglar - it just needs someone to walk in.
5. This is not hypothetical
In July 2026 SerpCtrl audited a live Baltic online-therapy platform, Pasaki.lv - a Latvian brand operated by the Lithuanian company MB "Pasikalbek," running a re-skinned platform licensed from the Canadian firm IheerU Digital Solutions Inc. What the audit found:
- The specialist data model has no field for a license, registration number, or diploma - it does not merely fail to display credentials, it does not store them.
- All 61 practitioner profiles are first-name-only, each self-asserting the protected title "psihologs" with nothing to verify against.
- The public state register that would confirm each practitioner is free to use, and is not used.
- The named data controller in the privacy policy is a company on another continent; the crisis disclaimer tells users to call a foreign emergency number, not 112.
- On logged-in, condition-revealing pages it runs advertising trackers with no consent mechanism at all - the exact identity-to-content data flowing to third parties.
Every ingredient in Section 4 is present, by construction, in a product taking real payments from real people in crisis today. The gap is not a thought experiment. It is a design decision, shipped.
6. What verification actually costs
Nothing meaningful. The register check is a free public lookup. Identity verification via national eID is a solved, standard integration. Displaying a registration number is a database column and a line of UI. Every part of the fix is cheaper than the marketing budget the same platforms spend to acquire the users they then fail to protect.
Which exposes the real inversion. Uber verifies its drivers. Airbnb verifies IDs. A bank runs KYC before it will hold your money. A platform that holds the most vulnerable people's darkest disclosures, and seats a stranger opposite them, verifies a first name. Risk-proportionality is upside down: the more sensitive the relationship and the more vulnerable the user, the less checking happens.
7. What a platform built for this looks like
The bar is not exotic. It is what "responsible" means once you take the two Vastaamo lessons together - seal the notes and check the stranger:
- Verify the practitioner at onboarding against the public register, capture the certificate field, and for supervised practitioners capture the named supervisor. Re-check on a schedule.
- Display the proof. Show the registration number so the client can confirm it themselves. Verification the user cannot see is not trust; it is another "just trust us."
- Verify identity, not just credentials. Bind the account to the real person via eID, so the listed clinician is provably the one in the room. Identify the therapist; you never need to unmask the patient.
- Encrypt so a breach is worthless. End-to-end, keys the server never holds - the Vastaamo fix, done properly.
- Localise the safety-critical details. The crisis number must be the right country's. The data controller must be a correctly identified, reachable, in-jurisdiction entity.
None of this is a competitive moat because it is clever. It is a moat because so few bother.
8. What Stoa does, and the floor we will not ship below
SerpCtrl builds Stoa, a mental-health regulation app now in TestFlight. We build it to both Vastaamo lessons at once - seal the notes and check the stranger. Because we are willing to publish this piece, it is only fair to publish our own bar, with an honest line between what ships today and what we are still building. That honesty is the point: a security claim you overstate is one you will be caught below.
In the app today (shipped):
- Local-first by default. Nothing leaves your phone unless you choose an account. Thought logs and crisis contacts never sync at all.
- Zero third-party tracking. No ads, no tracking pixels, no analytics SDKs, no selling data, no training ML on it - the exact inverse of the platform audited above.
- Pseudonymous by design. Your legal identity never enters the system. Anonymous IDs only; therapist and client connect by code, never by exchanging names.
- Consent built for Article 9. Five distinct, timestamped, withdrawable consent types for special-category data.
- EU residency, least privilege. Cloud data held in the EU, row-level security so you reach only your own, encrypted in transit and at rest.
The clinical layer we are building (committed, not yet all shipped):
- Exfiltration-worthless by design. Clinical content sealed to keys the server never holds - steal the whole database and you get ciphertext.
- Break the identity-to-content link. Content de-identified on the patient's own device before it is ever shared - "my brother," not a name - so even the intended reader never gets the identifying detail.
- One breach is not everyone. A compromised clinician account is bounded to that clinician's own consented caseload, never the whole system.
- Key is not login. Defeating the login does not yield the decryption key; every access is audit-logged and revocable.
- Verify the clinician, not the patient. Register check plus eID on the professional; the patient stays anonymous.
Why this is the minimum, not the ceiling:
- The breach model is extortion, not fraud. Perimeter security ("nobody gets in") is not a floor you can stand on. The floor has to be that stolen data is worthless.
- The harm is the linkage. A name alone is harmless; "abused at seven" alone is harmless; joined, catastrophic. The minimum is to break that join structurally, not to promise a wall.
- You cannot prove a wall; you can guarantee ciphertext. "Unbreakable" is unfalsifiable and eventually false. "The server holds no keys" is a property you can defend to a regulator.
- Trust is the whole product. Vastaamo did not pay a fine and move on - it went bankrupt. A single breach of this class ends the company, so the bar is the licence to exist, not a feature tier.
And the rule that makes the rest credible: we never say "anonymised" or "unbreakable." We state what a worst-case compromise still exposes - bounded, de-identified, pseudonymous, logged, revocable - because the platforms that overstate their security are the ones that end up in the headlines under it.
9. The asymmetry at the center of it
Therapy is the one relationship in which the client is least able to verify the provider. They arrive emotionally exposed, often in crisis, without the expertise to judge whether the person opposite is competent - or even real. Every other market lets the buyer inspect the goods. This one structurally cannot.
That is exactly why the system has to do the verifying. When a platform pushes that duty onto the user - "the register is public, check it yourself" - it has handed the most vulnerable person in the transaction the one job they are least equipped to do, and called it consent.
Vastaamo proved we can no longer leave the notes unencrypted. The next case will prove we cannot leave the door unlocked. Encrypt the conversation and verify the stranger - because a therapist you cannot verify is not a service. It is a breach that has not introduced itself yet.
Sources
- Vastaamo data breach - Wikipedia (en.wikipedia.org/wiki/Vastaamo_data_breach)
- Vastaamo hacker sentenced to six years, three months in prison - Helsinki Times
- Appeals court raises Kivimaki's sentence to nearly seven years - Yle News (yle.fi/a/74-20212466)
- Court clears former Vastaamo CEO Ville Tapio of data protection charges - Helsinki Times
- Hacked therapy centre's ex-CEO gets 3-month suspended sentence - Yle News (yle.fi/a/74-20027665)
- Latvia: Psihologu likums (likumi.lv/ta/id/290115); public register at viis.gov.lv/registri/psihologi
- Primary audit: SerpCtrl, "Pasaki.lv Security, Privacy & Compliance Audit," July 2026 (internal)
Disclaimer
This case study was prepared by the SerpCtrl team using publicly available information - including public court records and reporting on the Vastaamo data breach, Finnish and Latvian law, and the public Register of Psychologists (viis.gov.lv) - together with a passive, read-only review of the Pasaki.lv platform reflecting its technical and content state as of July 10, 2026. That review used only publicly accessible pages and a standard logged-in session; it involved no active exploitation, no attempt to access other users' data, and no security testing beyond passive observation. Supporting screenshots and records substantiating the claims made in this article are retained. SerpCtrl has no affiliation with Vastaamo, Pasaki.lv, MB "Pasikalbek," or IheerU Digital Solutions Inc. SerpCtrl does build Stoa, a mental-health application referenced in this article, and therefore has a commercial interest in this field; we disclose that openly rather than obscure it. If you see omissions or inaccurate information in this publication, please report it in writing to info@serpctrl.lv, and we will make changes if they are justified.