Finland’s most-wanted hacker nabbed in France
krebsonsecurity.com
krebsonsecurity.com
- He hacked the patient files of a psychotherapy center Vastaamo. This included therapy notes for more than 22.000 patients.
- First the hacker blackmailed the therapy center.
- Next he started blackmailing individual patients.
- Finally he released the files online revealing very private information on thousands of patients.
I can only imagine the horror felt by the people whose therapy notes were made public.
Not worth it
one of the benefits of therapy that you are missing out on is learning that what you are ashamed of is much less important than that you feel all that shame toward yourself. everybody else has much they are ashamed of, it's not a big deal
https://www.iltalehti.fi/digiuutiset/a/69314f2e-bb1c-4ea0-8a...
The problem with jailing CEOs is that even if it would work the first couple of times the other possible effect would be that people would do even more to brush their fuckups under the carpet...
The EU has got this right I think: massive fines in case of a breach to the point that the CEOs are starting to pay attention. That certainly isn't perfect but it is a step in the right direction.
Healthcare is particularly vulnerable and I'm always surprised that people in HC seem to think that they aren't a target. This is a huge mistake imo, there is massive blackmail potential in healthcare data.
CEO hires CISO. CISO makes a big splash, and spends a ton of time getting the business certified in various ways, to prove to CEO stuff is being done.
In reality, security remains atrocious at the tactical level, and the company hemorrhages security talent because no one wants to work for clueless assholes.
Ultimately, eventually, breach still happens, CISO falls on their sword, but is fine because they and CEO always knew this is what they were really being hired to do and compensation was engineered around that expectation.
--
What actually works is a gentle, gradual pressure to move to a better security posture (e.g. vaulted credentials, separate security domains, etc.), implemented over time as opportunity allows, preventing new vulnerabilities from being introduced by targeting development processes, and financially incentivizing developers throughout the company to report issues when they find them.
I might be in the minority here, but frankly I'd be -happy- to actually be able to see a therapist's notes on me. At least in my region, one of the first things you sign before any therapy begins usually contains a paragraph that such notes are 'IP' of the therapist/provider and thus something you as a patient are never allowed to see.
Fewer patients would be happy to see the doctor’s notes for all other patients including themselves.
Fewer still would appreciate having everyone, including non-patients, see not only their notes but all of the other patients in that practice.
When the case came to court, the defendants' first action was of course asking the court to suppress all evidence from the FBI because it was obtained illegally, as the criminals obviously had an expectation to the privacy of their correspondence, which was illegally violated. The court actually ruled that the messages are only admissible if they pertain to crimes that carry a maximum penalty of at least four years in prison, which is the same threshold that allows the Finnish law enforcement to use wiretapping.[2]
[1]: https://en.wikipedia.org/wiki/ANOM
[2]: https://www.hs.fi/kotimaa/art-2000008761772.html (paywalled & encrypted in Finnish)
There was a case in France where the suspect of a murder case fled to Germany which refused to extradite him. The father of the victim organised a kidnapping and left the guy attached in front of a French police station. The father was prosecuted for kidnapping, but that didn't help the alleged murderer who was then arrested and charged.
I don't know what the law is in Finland, but usually medical secrecy only covers specific stuff, and likely not the admission of a crime, unlike attorney-client privilege (which is specifically designed to cover crimes committed).
Incorrect. If you are really interested, the rules of evidence are outlined in the Code of Judicial Procedure, Chapter 17. Translation to English is available here: https://finlex.fi/en/laki/kaannokset/1734/en17340004_2019081...
The relevant part here is probably the last paragraph of section 25. It concerns the rules for admitting evidence that has not been given by the person themselves in an official investigation, and which has been obtained unlawfully. It is on page 97 in the linked PDF:
> [...] the court may use also evidence that has been obtained unlawfully unless such use would:
> * endanger the conduct of fair proceedings
> * taking into consideration the nature of the matter, the seriousness of the violation of law in obtaining the evidence
> * the significance of the method of obtaining the evidence in relation to its credibility
> * the significance of the evidence for deciding the matter
> * and the other circumstances.
Namely, considering that these documents were obtained in probably the most heinous possible violation of the person's privacy, it would not be possible for the court to admit them as evidence. That's anyway completely moot, as if it ever became publicly known that a prosecutor or police officer had read any of these documents it would be very scandalous in of itself.
But I personally relate more to the horror the hacker put himself through:
> security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder
> “It was a huge opsec [operational security] fail, because they had a lot of stuff in there — including the user’s private SSH folder, and a lot of known hosts that we could take a very good look at,”
What a huge flop! I can recall feelings myself publishing things I shouldn't, but the entire home directory, including private keys and everything? I'd die of shame.
Still, really terrible behavior from him, he deserves whatever punishment is coming for him.
If he physically broke in we wouldn't call him a nortorious lockpicker.
I mean read Stanley Milgram’s “Obedience to Authority” (with the actors who pretended to be shocked).
It was fascinating until he got to the theoretical implications. All cybernetic gobbledegook.
I prefer thinking of the “helmsman” of Ancient Greece when I hear Cyber/Kuber.
In the IPA, the sound of the French 'u' or German 'ü' is written with as 'y'. E.g. French "tu" -> [ty].
To speakers of languages without that sound, it often gets mapped to the vowel sound in the English word "loose".
So you can see what's happened here, "cybernetics" with the "Greek 'y'" pronounced as French "u" becomes "kubernetes".
I don't know if modern Greek still has that sound.
I love little realisations like this. Sometimes I wish I'd done linguistics instead of computer science.
Incidentally, the word "governor" comes from "kubernetes" as well.
https://en.wikipedia.org/wiki/Ancient_Greek_phonology#Vowel_...
It seems some varieties of Ancient Greek did have that sound
We don’t call him a hacker because he hasn’t been convicted. Your statement seems to miss the point of the parent comment.
Beyond reasonable doubt to take someone’s freedom. Not to privately judge them.
The problem is that people are numb to news about "hackers" because often it's some sort of dumb story about some teenager messing around in somebody else's network and a netsec or government bureaucracy overreacting rather than properly securing their network, whereas this case is basically an instance of terrorism. It should not be possible for me to be confused which kind of hacking story this is from the headline. If I had come across that headline in the wild I would almost certainly ignored it due to the above.
Other folks in the comments have brought up the term "cyber-criminal", which I think also fails this same test for exactly the same reasons.
The terms "hacker" and "criminal" are as mutually exclusive as "engineer" and "robber". Yes, maybe the robber knows how locks work so she can pick them, but "engineer" implies some level of ethics.
If you want to pass legislation to eliminate peoples privacy and justify the fascist governance structure (government + corporations working together) in deanonymising individuals, you have to show that it is special. This is what is really going on - its not actually some special new type of crime that the law hadn't catered for - that's just what its sold as.
So, because 'online is the problem' is actually a sales job, the more one heightens the risk of 'online', 'hackers', etc the easier it is to take everyone's privacy away on account of the perceived thread and the purported fix. People will be happy someone is doing something, given a terrible event (crime) occurred!
The reality is that crimes will always occur; the threats to safety are overblown and already covered by the law; the fix does not materialise as indicated. But if you were sold on the idea (as most are) and thought it would make a difference you will sign up (to less online freedom). It doesn't even matter that this is happened in Finland, or whether it even happened at all - as long as people think handing over more control to the governance structure is the solution.
The truth is that you bought into the ostensible excuses. No need to keep making that mistake though!
It's important to keep hammering it.
It seems the Internet does have a delete button. Has it been used again?
The owner of the company tried to sell it a few months later without declaring the data breach to the new owners and has been forced to pay €8M compensation: https://yle.fi/a/3-12479562
Digitising medical info is brilliant and extremely useful for anyone involved. Handoff between practitioners is seamless, and no more of the redundant "are you allergic to anything? any priors? are you taking any meds?", because the practitioner knows everything they need to (e.g. your dentist doesn't need to have access to your therapy notes, but should probably know all meds you're taking and all previous dentistry work done on you, wherever and wherever that happened). It would also allow for country-wide anonymous statistical analysis. Oh, everyone taking pill X is also having Y? Is there a problem there? A lot of people getting operated for A used to do Z, C, so maybe we need a better educational campaign so people know the risks? The possibilities - life saving, medical system improving, etc. are enormous.
It just needs to be handled with extreme care, because the risks are enormous. Security should be top notch, with strict access controls, anonymisation where needed, etc.
Both, digitizing general medical info and keeping specific bits in analog form for safety and security reasons are not mutually exclusive.
> Medical info should have NEVER being digitized.
Which i assumed to be talking about all medical info.
> The information contained is much more sensitive and at the same time they’re much less likely to be passed off between therapists unfiltered and unredacted.
Why not?
The question of whether or not these records will be digitized is no longer germane, it will happen, like it or not. But what can be done is that the systems that are used to store this information pass an external review to ensure that at least the basics required for keeping such critical information safe are met.
IMHO Zeekill represents the very worst kind of hacker: a greedy troll script kiddie who knows just enough to cause damage, and doesn't give a shit about the very real human cost.
I know it feels good to make fun of and denigrate him, but frankly a worse kind of hacker is one who really knows what he is doing
like script kiddie to me, is trying to DDOS somebody with ping
The bane of every criminal. You only have to make one mistake to get caught and there are many chances to make that mistake.
Many criminals on the run assume they’re smart, but luck plays a big role in getting caught or not…I mean, this guy got caught because of an unrelated case of domestic violence.
An acquaintance of mine tried to dodge his mandatory military service by moving to the neighboring country and would (foolishly) drive to his family across the border every now and then thinking that because Schengen has no borders he would never get caught.
And it worked for a couple of years, until one day when a police car stopped him for a busted tail light and handed him over to the military police.
If you're gonna break the law, you at least gotta be smart and careful about it.
Hence the always-true adage: If you're gonna break the law, only break one law at a time, not multiple.
Now, if you manage to hide your crime too...
There's a great scene from The Wire where this is discussed: https://www.youtube.com/watch?v=E2Fv-nJCfrk
There used to be a user on HN, going by the nickname "ryanlol" [0] who seemed to have (had) good hacking knowledge. Could be the same person, could be not. But they had good comments here and there, was fun to read back then.
https://news.ycombinator.com/threads?id=nachash
He didn't take that advice.
He's been on HN under a large number of accounts, in particular giving people advice on obtaining alternate identification papers (Romania was mentioned in particular).
https://news.ycombinator.com/item?id=34156119
So much for that I guess.
The first 10 are afaik accurate, the last stopped posting 3 days ago so that's a point of evidence.
Whoa. Just 11 years old he started.
Got busted after a domestic violence call, after a night out. Just, a pathetic life.
The guy obviously need psychiatric advice and "hacked" then blackmail a psychiatric institute.
But good job by the Courbevoie police. If it was any city north of Asniere i would have been more than impressed by the changes of our police force, but still, responding quickly to domestic violence even in a rich city is an improvement compared to five years ago. Still nowhere close to Spain, but baby steps.
I'd argue that's exactly what he did. He's just gone for the Mitnick method.
Very likely no, he could not. Being able to harm people does not imply ability to secure systems. Nor ability to learn advance tech while we are at it. Nor ability to obey contractual limits if you are red team.
And it would be pretty idea to employ person with such a bad judgement in any of those positions anyway.
Although posts about relatively young hackers who went the rogue black hat route always intrigue me.
I used to be a super curious script kiddy but fortunately found my solace in programming (relatively unharmful) scripts for games and private servers that'd only affect virtual economies.
But I also used to stroll gray/black hat forums out of curiosity and always wonder where I would've eventually end up if I did go down that path.
Fortunately, I'm in FANG now and make good bucks to never have to consider black hat again.
It's just in the back of my mind: what if ...?
One of the things that you learn as you grow older is that you can't be successful and have a conscience at the same time in this world. Software developers are fortunate enough to be able to scrape out a comfortable existence without stooping too far, but don't kid yourself: the large TechCos that sign our paychecks and buy our startups are not paragons of virtue.
Large TechCos can - for now - not be jailed but you can and you will, see TFA.
Less blatantly evil doesn't mean you're going to walk away free, besides, you'll be a blackmail target for life.
Oh, and it is quite possible to both be successful and to have a working conscience.
https://camas.unddit.com/#{%22author%22:%22uhx%22,%22resultS...
https://camas.unddit.com/#{%22author%22:%22uhxuhxuhx%22,%22r...
A bunch of IRC logs too:
https://google.com/?q=%22zeekill%22+site%3Apastebin.com
Including one where he basically extorts one the founders of ImageShack.
He has left quite the trail.
When crimes perpetuated online can effect so many people, can we stop treating them like regular crimes. That's ridiculous.
I might aswel defraud as many people as possible before 18 years and basically get away with it.
People seeing race/ethnic stuff here are severely mistaken.
except when they do of course.
You can also argue that he could have gone the bug bounty route if he could, but didn't have the skills.
This like advocating, "We should stop arresting people for gun violence. We should pay them instead."
The vast majority of these "hackers" just happen to be more handy with the digital equivalent of a gun and have more propensity for crime than your average Joe. Their "tell us what and how" would hardly worth your time, nevermind paying.
no shit sherlock
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.