Your Data May Already Be Compromised. The Vastaamo Breach Exposed 30,245 Patient Records.
Your therapist's notes may already be in the hands of strangers. The Vastaamo breach, which HEROIC analysts have been monitoring since it emerged publicly in October 2020, exposed the records of 30,245 patients at a Finnish psychotherapy provider. The original security incident occured between late 2018 and early 2019, when an attacker gained access to Vastaamo's database. The stolen data included email addresses, full names, and social security numbers. What made this breach partcularly devastating was what else was taken: detailed notes from private psychotherapy sessions, among the most sensitive personal records a person can have.
When Therapy Notes and Social Security Numbers Land Online
This breach gave attackers access to some of the most personal information imaginable. Social security numbers enable full identity theft, allowing criminals to open credit accounts, file fraudulent tax returns, and impersonate victims with government agencies. But the therapy session notes went further, handing attackers highly personal details that were used to directly blackmail patients. Affected individuals recieved threats demanding ransom payments in exchange for keeping their mental health history private.
What Was Exposed in the Vastaamo Breach
- Email Address
- Social Security Numbers
- First Name
- Last Name
Why a Healthcare Database Breach Can Follow You for Life
Financial fraud and identity theft are serious enough, but a breach involving mental health records creates a seperate category of long-term harm. Social security numbers cannot be changed easily, meaning the risk of identity theft persists for years. Attackers used the stolen data not just to sell on dark web markets, but to personally contact and extort victims, threatening to expose their therapy notes to family, employers, or the public. This is credential stuffing and extortion combined with deeply personal leverage, representing one of the most harmful types of breach a person can experience.
How a Database Breach Works
A database breach happens when an unauthorized party gains access to a company's internal records, often by exploiting a security vulnerability, a misconfigured server, or weak access controls. In Vastaamo's case, the attacker accessed the therapy service's patient database over an extended period beginning in 2018. Once the data was in their possession, they first attempted to extort the company, then pivoted to targeting individual patients directly when the company did not comply.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against a database of over 400 billion leaked records, including breaches involving sensitive personal and health-related data. If you or someone you know was a patient at Vastaamo or another healthcare provider that has experienced a breach, scan your email now to see what may have been exposed.
Breach Breakdown
30,245 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds