{"id":23407,"date":"2023-11-16T13:18:16","date_gmt":"2023-11-16T21:18:16","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/11\/16\/news-17137\/"},"modified":"2023-11-16T13:18:16","modified_gmt":"2023-11-16T21:18:16","slug":"news-17137","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/11\/16\/news-17137\/","title":{"rendered":"Alleged Extortioner of Psychotherapy Patients Faces Trial"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Thu, 16 Nov 2023 19:59:14 +0000<\/strong><\/p>\n<p>Prosecutors in Finland this week commenced their criminal trial against <strong>Julius Kivim\u00e4ki<\/strong>, a 26-year-old Finnish man charged with extorting a once popular and now-bankrupt online psychotherapy practice and thousands of its patients. In a 2,200-page report, Finnish authorities laid out how they connected the extortion spree to Kivim\u00e4ki, a notorious hacker who was <a href=\"https:\/\/krebsonsecurity.com\/2015\/07\/finnish-decision-is-win-for-internet-trolls\/\" target=\"_blank\" rel=\"noopener\">convicted in 2015<\/a> of perpetrating tens of thousands of cybercrimes, including data breaches, payment fraud, operating a botnet and calling in bomb threats.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-61773\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png\" alt=\"\" width=\"750\" height=\"357\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png 2936w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-768x366.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-1536x731.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-2048x975.png 2048w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-782x372.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p>In November 2022, Kivim\u00e4ki was charged with attempting to extort money from the <strong>Vastaamo Psychotherapy Center<\/strong>. In that breach, which occurred in October 2020, a hacker using the handle \u201cRansom Man\u201d threatened to publish patient psychotherapy notes if Vastaamo did not pay a six-figure ransom demand.<\/p>\n<p>Vastaamo refused, so Ransom Man shifted to extorting individual patients \u2014 sending them targeted emails threatening to publish their therapy notes unless paid a 500-euro ransom. When Ransom Man found little success extorting patients directly, they uploaded to the dark web a large compressed file containing all of the stolen Vastaamo patient records.<\/p>\n<p>Security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder, where investigators found many clues pointing to Kivim\u00e4ki\u2019s involvement. By that time, Kivim\u00e4ki was no longer in Finland, but the Finnish government nevertheless <a href=\"https:\/\/krebsonsecurity.com\/2022\/11\/hacker-charged-with-extorting-online-psychotherapy-service\/\" target=\"_blank\" rel=\"noopener\">charged Kivim\u00e4ki in absentia with the Vastaamo hack<\/a>. The 2,200-page evidence document against Kivim\u00e4ki suggests he enjoyed a lavish lifestyle while on the lam, frequenting luxury resorts and renting fabulously expensive cars and living quarters.<\/p>\n<p>But in February 2023, Kivim\u00e4ki was <a href=\"https:\/\/krebsonsecurity.com\/2023\/02\/finlands-most-wanted-hacker-nabbed-in-france\/\" target=\"_blank\" rel=\"noopener\">arrested in France<\/a> after authorities there responded to a domestic disturbance call and found the defendant sleeping off a hangover on the couch of a woman he&#8217;d met the night before. The French police grew suspicious when the 6&#8242; 3&#8243; blonde, green-eyed man presented an ID that stated he was of Romanian nationality.<\/p>\n<div id=\"attachment_65661\" style=\"width: 692px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-65661\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-65661\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/11\/kivimaki-romainianid.png\" alt=\"\" width=\"682\" height=\"466\" \/><\/p>\n<p id=\"caption-attachment-65661\" class=\"wp-caption-text\">A redacted copy of an ID Kivimaki gave to French authorities claiming he was from Romania.<\/p>\n<\/div>\n<p>Finnish prosecutors showed that Kivim\u00e4ki&#8217;s credit card had been used to pay for the virtual server that hosted the stolen Vastaamo patient notes. What&#8217;s more, the home folder included in the Vastaamo patient data archive also allowed investigators to peer into other cybercrime projects of the accused, including domains that Ransom Man had access to as well as a lengthy history of commands he&#8217;d executed on the rented virtual server.<\/p>\n<p>Some of those domains allegedly administered by Kivim\u00e4ki were set up to smear the reputations of different companies and individuals. One of those was a website that claimed to have been authored by a person who headed up IT infrastructure for a major bank in Norway which discussed the idea of legalizing child sexual abuse.<\/p>\n<p>Another domain hosted a fake blog that besmirched the reputation of a Tulsa, Okla. man whose name was attached to blog posts about supporting the &#8220;white pride&#8221; movement and calling for a pardon of the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Timothy_McVeigh\" target=\"_blank\" rel=\"noopener\">Oklahoma City bomber Timothy McVeigh<\/a>.<\/p>\n<p>Kivim\u00e4ki appears to have sought to sully the name of this reporter as well. The 2,200-page document shows that Kivim\u00e4ki owned and operated the domain <strong>krebsonsecurity[.]org<\/strong>, which hosted various hacking tools that Kivim\u00e4ki allegedly used, including programs for mass-scanning the Internet for systems vulnerable to known security flaws, as well as scripts for cracking database server usernames and passwords, and downloading databases.<span id=\"more-65630\"><\/span><\/p>\n<div id=\"attachment_65662\" style=\"width: 654px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-65662\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-65662\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/11\/kos-org-bash.png\" alt=\"\" width=\"644\" height=\"866\" \/><\/p>\n<p id=\"caption-attachment-65662\" class=\"wp-caption-text\">Ransom Man inadvertently included a copy of his home directory in the leaked Vastaamo patient data. A lengthy history of the commands run by that user show they used krebsonsecurity-dot-org to host hacking and scanning tools.<\/p>\n<\/div>\n<p><strong>Mikko Hypp\u00f6nen<\/strong>, chief research officer at WithSecure (formerly F-Secure), said the Finnish authorities have done &#8220;amazing work,&#8221; and that &#8220;it&#8217;s rare to have this much evidence for a cybercrime case.&#8221;<\/p>\n<p><strong>Petteri J\u00e4rvinen<\/strong> is a respected IT expert and author who has been following the trial, and he said the prosecution&#8217;s case so far has been strong.<\/p>\n<p>&#8220;The National Bureau of Investigation has done a good job and Mr Kivim\u00e4ki for his part some elementary mistakes,&#8221; J\u00e4rvinen <a href=\"https:\/\/www.linkedin.com\/posts\/petterij_vastaamo-activity-7130135333010046976-81_v\" target=\"_blank\" rel=\"noopener\">wrote<\/a> on LinkedIn. &#8220;This sends an important message: online crime does not pay. Traces are left in the digital world too, even if it is very tedious for the police to collect them from servers all around the world.&#8221;<\/p>\n<p><strong>Antti Kurittu<\/strong> is an information security specialist and a former criminal investigator. In 2013, Kurittu worked on an investigation involving Kivim\u00e4ki\u2019s use of the <a href=\"https:\/\/krebsonsecurity.com\/tag\/zeus-trojan\/\" target=\"_blank\" rel=\"noopener\">Zbot botnet<\/a>, among other activities Kivim\u00e4ki engaged in as a member of the hacker group <a href=\"https:\/\/www.exploit-db.com\/papers\/25306\" target=\"_blank\" rel=\"noopener\">Hack the Planet<\/a> (HTP). Kurittu said it remains to be seen if the prosecution can make their case, and if the defense has any answers to all of the evidence presented.<\/p>\n<p>&#8220;Based on the public pretrial investigation report, it looks like the case has a lot of details that seem very improbable to be coincidental,&#8221; Kurittu told KrebsOnSecurity. &#8220;For example, a full copy of the Vastaamo patient database was found on a server that belonged to Scanifi, a company with no reasonable business that Kivim\u00e4ki was affiliated with. The leaked home folder contents were also connected to Kivim\u00e4ki and were found on servers that were under his control.&#8221;<\/p>\n<p>The Finnish daily <em>yle.fi<\/em> <a href=\"https:\/\/yle.fi\/a\/74-20059985\" target=\"_blank\" rel=\"noopener\">reports<\/a> that Kivim\u00e4ki&#8217;s lawyers sought to have their client released from confinement for the remainder of his trial, noting that the defendant has already been detained for eight months.<\/p>\n<p>The court denied that request, saying the defendant was still a flight risk. Kivim\u00e4ki&#8217;s trial is expected to continue until February 2024, in part to accommodate testimony from a large number of victims. Prosecutors are seeking a seven-year sentence for Kivim\u00e4ki.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2023\/11\/alleged-extortioner-of-psychotherapy-patients-faces-trial\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Thu, 16 Nov 2023 19:59:14 +0000<\/strong><\/p>\n<p>Prosecutors in Finland this week commenced their criminal trial against Julius Kivim\u00e4ki, a 26-year-old Finnish man charged with extorting a once popular and now-bankrupt online psychotherapy practice and thousands of its patients. In a 2,200-page report, Finnish authorities laid out how they connected the extortion spree to Kivim\u00e4ki, a notorious hacker who was convicted in 2015 of perpetrating tens of thousands of cybercrimes, including data breaches, payment fraud, operating a botnet and calling in bomb threats.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,28511,27900,30513,16696,30514,28514,30515],"class_list":["post-23407","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-antti-kurittu","tag-julius-kivimaki","tag-mikko-hypponen","tag-neer-do-well-news","tag-petteri-jarvinen","tag-vastaamo-psychotherapy-center","tag-withsecure"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23407"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23407\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23407"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23407"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}