so, the company was Vastaamo. was because it got bankrupt after the breach, and GDPR violations.

the “hacker”(or rather cracker) was extradited from France to Finland.
you can read about how terrible the company’s security was here: https://tietosuoja.fi/en/-/administrative-fine-imposed-on-psychotherapy-centre-vastaamo-for-data-protection-violations

or watch mental outlaw’s video on the matter, or the Wikipedia article on the breach.

now there are several things that shouldn’t have happened (e.g.: don’t do these things on your main OS, have root access disabled, etc.), but I’ll leave that to you experts.

    • lemmesay@discuss.tchncs.deOP
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      it’s almost as if company begged to get hacked. but imagine the horror those people whose data was leaked had to go through. they open up to their psychologist and now everyone knows about it.