www.hs.fi Vastaamo Hacker Kivimäki Appeals Six-Year Sentence for Data Breach and Extortion
Article Content
- •Julius Kivimäki was sentenced for hacking Vastaamo and extorting its clients.
- •The attack compromised data of around 33,000 individuals, including sensitive information.
- •Kivimäki is appealing his sentence to the Supreme Court while currently residing abroad.
Julius Aleksanteri Kivimäki, 28, has filed an appeal to the Supreme Court regarding his sentence of 6 years and 11 months for hacking and extortion related to the Vastaamo psychotherapy center. The Helsinki Court of Appeals increased his sentence by eight months, citing the premeditated nature of his crimes and the significant financial gain he sought. Kivimäki was convicted of multiple offenses, including aggravated data breach, attempted extortion, and the unlawful dissemination of private information affecting approximately 33,000 individuals. The attack occurred in November 2018 when Kivimäki infiltrated Vastaamo's systems, copied patient data, and later extorted victims in 2020. His lawyer indicated that Kivimäki is currently abroad and has not disclosed his location. The case is significant in Finnish criminal history due to its scale and the sensitive nature of the data involved.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Vastaamo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…