Cybercrime
,
Fraud Management & Cybercrime
Vastaamo Hacker Aleksanteri Kivimäki Is Free, For Now

A Helsinki court ordered the release of Finland’s most notorious hacker pending the resolution of his appeal of an April 2024 conviction stemming from the theft of psychotherapy records of 33,000 individuals.
See Also: Why Cyberattackers Love ‘Living Off the Land’
The Helsinki Court of Appeal on Thursday ordered the release of Aleksanteri Tomminpoika Kivimäki after determining that he had already spent too much time in pretrial detention, reported Finnish newspaper Helsingin Sanomat.
Kivimäki was convicted last year for hacking into now-defunct psychotherapy chain Vastaamo, assuming the moniker “ransom_man” to blackmail patients and publish patient records online. At least one suicide reportedly resulted from the incident. Prosecutors said he carried out the breach between November 2018 and March 2019 (see: Finnish Hacker Kivimaki Found Guilty in Vastaamo Hack).
The District Court of Länsi-Uusimaa sentenced him to six years and three months in prison for aggravated data breach. The appeals court began hearing Kivimäki’s bid to overturn the conviction in August, along with prosecutor’s demand that the sentence now be raised to seven years.
The court ruled Thursday that the conditions for keeping him detained were no longer valid, Finnish news outlet MTV reported. Under Finnish law, first-time offenders are eligible for parole after serving half their sentence, and can also apply for supervised release six months before that. Kivimäki’s lawyer argued he had already exceeded these limits.
“I expected this decision. It feels good. I will participate in the Court of Appeal sessions now,” Kivimäki told MTV on Thursday.
Vastaamo went bankrupt after ransom_man published therapy session notes of 300 patients and later emailed victims an extortion demand of 200 euros in cryptocurrency, which he said would increase to 500 euros after 24 hours. Vastaamo received an extortion demand of 450,000 euros. Kivimäki’s bank account showed evidence of several payments during the time ransom_man was active, prosecutors said (see: Prosecutors Add to Evidence Against Alleged Vastaamo Hacker).
In addition, the hacker made the mistake of not masking his IP address through a virtual private network, leading authorities to trace ransom_man to Kivimäki.
Kivimäki has contested the evidence, arguing that is based on fabricated proof (see: Finnish Hacker Denies Role In Psychotherapy Clinic Attack).
Kivimäki, under the alias of “zeekill” and “Ryan,” was earlier part of a distributed denial-of-service gang know as Lizard Squad that, among other attacks, overwhelmed the servers for Xbox Live and the PlayStation Network on Christmas Day 2014.
