the breached db of psychotherapycentre #vastaamo had 100 new names added to it last night, timestamp 21-Oct-2020 22:11
total customers in the dump: 200
Dump includes very sensitive material incliding full name, SSN, email, phonemumber, meeting notes @CERTFI @troyhunt
Dump includes underage kids as well.
Breacher said he/she will drop 100 per day until the ransom of 40BTC is met.
{not confirmed, speculation}
Breacher may have cloned the original imageboard page and dumped it on deepweb website. Included are adform cookies and other trackers with identifiable info. May be from the breacher or just some user who wanted to share the data around.
Darknet imageboard thread who has presumably the breacher talking also has offered to delete some info for 0.05btc and has changed contact to vastaamo@cock.li (which is down as of 22nd @ 15.19)
Potential BTC wallet
100 more accounts added to DB along with a tar file with each customer. There are now a total of 300 customers leaked.
Breacher was asked about are there any "Any big celebrities or politicians?", they replied with customers who used their Finland police email.
{not confirmed}
Onion site for the DB is down. Potentially due to ransom of 40BTC paid
Its a good that the onion site is down, would be interesting to know did #vastaamo pay the ransom, or did KRP just catch the breacher and kill the onion site.
I didnt see other 40btc transactions in the blockchain
Before being downed, a 10 gig file was uploaded at 2:01. Someone allegedly was able to download ~1gig before cut off. Had thousands of customers in there.
.onion site for the leaked data keeps going back up every now and then.
its most likely getting actively hammered with requests so that it falls into a DOS state.
Extortion emails popping up from smileup(.)site domain requesting 200€ worth of BTC or victim has their data leaked
Files with their details regarding customers of #vastaamo using poliisi(.)fi email are getting/got leaked
(re-edited photo, saw that i didnt completely cover up the last name of one victim, sorry about that)
from what I've gathered, allegedly there is few partial copies of the 10gb DB dump existing beside the full one ransom_man has which pops up sometimes
One of the holders leaked multiple files onto the imageboard
Some tech for various domains owned by #vastaamo
potilasrekisteri has Apache 2.4.18 from 2015
mdpackages has Apache 2.4.29 from 2017
Vastaamo main site powered by PHP 5.5.21 from 2015
A #vastaamo tarbal with 31 980 patientstories was dropped to a filesharing site and the link to finnish darknet forums at around midnight Finland time
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.
