#000000 Profile picture
Oct 22, 2020 16 tweets 5 min read Read on X
the breached db of psychotherapycentre #vastaamo had 100 new names added to it last night, timestamp 21-Oct-2020 22:11
total customers in the dump: 200
Dump includes very sensitive material incliding full name, SSN, email, phonemumber, meeting notes @CERTFI @troyhunt
Dump includes underage kids as well.
Breacher said he/she will drop 100 per day until the ransom of 40BTC is met.
{not confirmed, speculation}
Breacher may have cloned the original imageboard page and dumped it on deepweb website. Included are adform cookies and other trackers with identifiable info. May be from the breacher or just some user who wanted to share the data around.
Darknet imageboard thread who has presumably the breacher talking also has offered to delete some info for 0.05btc and has changed contact to vastaamo@cock.li (which is down as of 22nd @ 15.19) Image
Potential BTC wallet Image
100 more accounts added to DB along with a tar file with each customer. There are now a total of 300 customers leaked.
Breacher was asked about are there any "Any big celebrities or politicians?", they replied with customers who used their Finland police email. Image
{not confirmed}
Onion site for the DB is down. Potentially due to ransom of 40BTC paid Image
Its a good that the onion site is down, would be interesting to know did #vastaamo pay the ransom, or did KRP just catch the breacher and kill the onion site.
I didnt see other 40btc transactions in the blockchain
Before being downed, a 10 gig file was uploaded at 2:01. Someone allegedly was able to download ~1gig before cut off. Had thousands of customers in there. Image
.onion site for the leaked data keeps going back up every now and then.
its most likely getting actively hammered with requests so that it falls into a DOS state.
Extortion emails popping up from smileup(.)site domain requesting 200€ worth of BTC or victim has their data leaked Image
Files with their details regarding customers of #vastaamo using poliisi(.)fi email are getting/got leaked
(re-edited photo, saw that i didnt completely cover up the last name of one victim, sorry about that) Image
from what I've gathered, allegedly there is few partial copies of the 10gb DB dump existing beside the full one ransom_man has which pops up sometimes
One of the holders leaked multiple files onto the imageboard
Some tech for various domains owned by #vastaamo
potilasrekisteri has Apache 2.4.18 from 2015
mdpackages has Apache 2.4.29 from 2017
Vastaamo main site powered by PHP 5.5.21 from 2015 Image
A #vastaamo tarbal with 31 980 patientstories was dropped to a filesharing site and the link to finnish darknet forums at around midnight Finland time

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with #000000

#000000 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(