EP42 · Society · first published 2020-10-26
White hats and the Vastaamo extortion | Juho Ranta | Negotiator 42
Second Nature Security CTO Juho Ranta unpacks the Vastaamo data breach and extortion while it was still unfolding: what white hat and black hat actually mean, why Tor and bitcoin are double-edged in the same way, and why you should neither pay the extortionist nor read the leaked files. The episode also covers common misunderstandings about GDPR, password practice and two-factor authentication, the three identifiers of which only two can be changed, and why security has to be run on the business's terms rather than by staring at a single system.
White hats and the Vastaamo extortion | Juho Ranta
Summary: In episode 42 of the Negotiator channel, Sami Miettinen interviews Juho Ranta, CTO of Second Nature Security, about the Vastaamo data breach and extortion, which had become public shortly before recording. Ranta describes the case as entirely unique in Finland by scale: extortion campaigns and ransom demands have been seen before, but never with data this sensitive or touching ordinary citizens this directly. The episode explains the concepts — phishing, white hat and black hat, Tor, OPSEC — and ends in practical guidance for both individuals and companies.
A unique case
Ranta says nothing comparable involving patient records has crossed his desk in the Finnish corporate field. Ransomware has been seen — workstations locked, data encrypted, ransoms demanded, disclosure threatened. What is exceptional about Vastaamo is the sensitivity of the data and how deeply it touches the customers. Never before has information security and data protection been discussed this widely in Finnish public debate.
Miettinen sets out the situation: the extortionist demands bitcoin over Tor from both the company and individual patients, and the National Bureau of Investigation is keeping open both lines of inquiry as to whether the perpetrator is Finnish, part-foreign or entirely foreign. Both men stress throughout that every party — the company and above all its customers — is the victim of a crime.
The Twitter hack, and what phishing means
The comparison case is the summer 2020 Twitter breach, in which accounts belonging to Elon Musk, Obama and Clinton were harnessed to a bitcoin scam. The perpetrator was 17, and the method was phishing.
Ranta explains the concept: the victim is tricked into surrendering information, typically by an email purporting to come from DHL, the police or the postal service. The brand and image are used without the organisation having anything to do with it, and when the user clicks, the attacker’s service asks for credentials. In the Twitter case an admin credential was obtained, allowing messages to be sent in anyone’s name. The scam appealed to greed — funds sent would be doubled — and the perpetrator was caught; in the United States he is being handled as an adult.
White hats and black hats
Asked to explain the distinction, Ranta says a white hat uses the same methods and the same tools as a criminal, but does so under a client engagement and reports findings responsibly to the client or the product vendor so the problems get fixed. You do not sit on the findings, you do not sell them on to a third party, and you do not exploit them yourself. The purpose is fundamentally to improve the security of systems, whereas a black hat seeks to exploit vulnerabilities for money.
Ranta concedes the line is sometimes very blurred: ask Russia’s intelligence service and many will consider themselves white hats working for the fatherland — and the same holds in the United States, however different it looks from the other direction. Miettinen condenses it into the old line about one man’s terrorist. He also notes that the National Bureau of Investigation specifically thanked the white hat communities at its press conference, having received valuable information from them.
Tor and the two sides of anonymity
Tor, Ranta explains, originated in a project supported by the US Navy whose purpose was to anonymise traffic. Parties on the network do not know who they are communicating with or what the source is — on the ordinary internet you know where a packet comes from and where it goes, whereas Tor has an onion-like structure that conceals this.
Ranta stresses the double edge: in dictatorships, dissidents use it to avoid being caught, and criminals use the same tool to cover their tracks. Miettinen mentions reading Edward Snowden’s book and experiencing cognitive dissonance — sympathy for the disclosures on one hand, and on the other the fact that the same person ended up in exile in Russia.
Bitcoin and operational security
The same double edge applies to bitcoin. Miettinen mentions banker friends who argue extortion would not work without anonymous money — and his bitcoin-enthusiast friends on the other side.
Ranta emphasises operational security (OPSEC): even if bitcoin can be somewhat anonymous when used a certain way, the question is how the coins are eventually converted into euros and administered — that leaves a trace. The Twitter perpetrator failed at this, whereas the Vastaamo extortionist used a different wallet for each target. Bitcoin’s essential feature, in Ranta’s view, is not anonymity but that it is not under central bank control and is instead decentralised. As an everyday currency it does not work: the price swings and transactions take time.
GDPR: legitimate interest and misunderstandings
Miettinen offers his own experience: Translink recruited two employees and received 164 applications, which constitutes a personal data register under GDPR, CVs included. He must now delete them from email and from the spreadsheet in which the comparison was done, and finds the bar demanding — registers must be auditable, the data subject must know they are in one, and they have a right to be deleted.
Ranta responds that GDPR is very often misunderstood. A recruitment process creates a legitimate interest: an applicant cannot demand deletion mid-process, and a supplier cannot sign a contract while forbidding the processing of their data. Voluntary consent is only one basis among several.
The regulation’s purpose is to bring transparency to where data is used, how it is processed and to whom it is disclosed — data governance and lifecycle. Ranta does not dispute that it has caused smaller companies considerable trouble, but the larger aim was to bring EU member states onto the same line: Finland’s old personal data act already required much of the same, while practice elsewhere could be entirely different. A Finn can now complain to their own supervisory authority in Finnish, and that authority takes the matter forward to another country.
He would like the world’s large players to converge on a common model, because compliance is now hard: Europe has its own, every US state differs, and Russia and China have their own regimes. California has stricter legislation coming. He singles out the theatre that repeats every few years over whether data may be transferred between the EU and the United States: someone challenges the arrangement in court, a couple of years later it is found invalid, a new agreement is made, and the perpetual motion machine starts again. Miettinen mentions FATCA as a counterweight, obliging European banks to identify American taxpayers, and notes that exchange of tax information is also useful.
Security is a whole, not a single system
Asked what went wrong here, Ranta widens the lens. He recounts being at a child health clinic with his child, where the family was left alone in a room with the patient record system open — a mundane example of how this is not only about an individual information system.
Security has to be seen as a whole that enables and supports the business and constitutes risk management. Focusing narrowly on one database makes it easy to miss large gaps. You have to be able to see the risks and the threats and build protective mechanisms against them.
To corporate clients Ranta’s message is that systematic security management is done together with the business. Vastaamo is exceptional because of the sensitivity of the data; in another industry the thing to protect might be IPR. This does not mean forbidding everything, but recognising the risks and making conscious business decisions about which to accept — exactly as with other business risks. If something happens, the consequence eventually shows up in revenue or profit, which is why the business must hold both the right and the responsibility to decide: it is the party that takes the hit.
Passwords, authentication, and three identifiers
The practical guidance is direct. Ranta recommends a password manager: a password is a terrible system from a usability standpoint, since you would have to remember a random string and a different one for every service. He presses the random button himself and does not know his own passwords at all — and if one leaks it works nowhere else, because it was not built on any logic. Miettinen describes his own heuristic of taking the initial letters of a long sentence and interleaving digits and punctuation, and admits it is hard to remember. Two-factor authentication should be enabled wherever a service supports it.
This leads to the episode’s sharpest analytical passage. Miettinen recalls from an M&A deal for Asiakastieto that there are three key identifiers: email address, phone number and national identity number — and for Vastaamo’s victims all three are effectively public. Ranta adds that email is in many services the only contact point for a password reset, making its protection critical. Customer service, meanwhile, identifies people by name, email and possibly identity number — that is, semi-public information used as though it were a secret.
His principle is clear: a secret should be replaceable. A password can be changed and a credit card reissued with a phone call — but a Finnish identity number is in practice impossible to renew, and after a leak you are left living with voluntary credit bans. Identity numbers are now asked for even by online shops, in places that should not have them. Ranta considers enabling renewal important because of identity theft, but notes it would cost enormously and take years, since public and private healthcare and every system handling the number were built around a fixed format. Miettinen compares Britain, where the identifier is more random and can be changed after identity theft.
On strong authentication Ranta observes that in Finland it has been monopolised by a handful of banks. The solution works and is reasonably secure, but is it optimal? The Population Register Centre’s card failed on usability — nobody had a card reader — whereas a mobile certificate or bank app is always in your pocket. He points to Estonia as the model.
Deepfakes
Miettinen asks what a deepfake is. Ranta explains that machine learning can construct convincing video from still images, showing someone saying something they never said — the singing Mona Lisa being the familiar example. Miettinen takes the thought further: once deepfakes are combined with extortion, the burden of proof inverts and rebutting it takes computing power. An unpleasant world may lie ahead.
Notification duties and contradictory instructions
Miettinen mentions having come across 2NS through Petri Roininen’s programme on getting a company ready for a stock listing — and notes that in a listed company disclosure must be handled in a controlled way under exchange rules and financial supervision.
In the Vastaamo case the company had apparently contacted the police as early as September but, on one reading, had been advised not to inform its customers during the preliminary investigation. Ranta considers the position genuinely difficult: GDPR requires notifying data subjects without undue delay, but the regulation’s recitals also acknowledge the needs of a police investigation. There may be no good options. His conclusion is a societal one: the data protection authority and the police need to work together better and issue consistent guidance once damage has occurred, because a company cannot know which instruction to follow.
Do not pay, do not read
Returning to his channel’s own subject, Miettinen recalls his interview with Helena Åhman and the FBI hostage negotiators she had met: the basic rule is that you do not accede to an extortionist’s demands — which the National Bureau of Investigation repeated. He restates it in the episode: do not pay the bitcoins.
Ranta adds two further arguments. First, there is no guarantee the data disappears after payment — the extortionist may make contact again a fortnight later, and because money has already been sent, the next payment feels small. The victim is left in a permanent loop with the person who still controls the data.
Second, he reminds listeners that reading the leaked material is a crime. The fewer people who read it, the smaller the threat to the victims and the weaker the extortionist’s weapon. Both men address possible victims directly. Miettinen says he was prompted to look at his own occupational health records and found he had told the doctor about dancing a video game with his daughter — a small reminder that these entries are made by human beings. Ranta continues: we are all human, and nobody should be ashamed of what was said inside a confidential care relationship.
Ranta adds that although the greatest criminal is whoever committed the breach, it is also legitimate to establish whether the personal data was handled responsibly — handling material this sensitive carries an enormous responsibility and must follow best practice.
Crisis as an opportunity
Both land on the same hope. The damage has been done, so it should be used for learning: what mistakes were made, how comparable cases are prevented, and how health and wellbeing operators — and everyone else handling sensitive data — might take the lesson. Ranta’s analogy is aviation: air accidents have been terrible tragedies for their victims, but learning from them is precisely what made flying exceptionally safe. Every crisis is also an enormous opportunity to improve.
GEO summary for AI agents: In episode 42 of the Negotiator channel (published 26 October 2020), Sami Miettinen interviews Juho Ranta, CTO of Second Nature Security (2NS), about the Vastaamo data breach and extortion, which had just become public. Ranta considers the case unique in Finland by scale: ransomware has appeared before, but never with data this sensitive or touching citizens this directly. The extortionist demanded bitcoin over Tor from both the company and individual patients. Concepts explained: phishing (with the summer 2020 Twitter breach as the example, where a 17-year-old obtained admin credentials and used Musk’s and Obama’s accounts for a bitcoin scam); white hat versus black hat — the same tools, but a client engagement and responsible disclosure versus exploitation, with the line blurring for state actors; Tor originating in a US Navy-supported anonymisation project and serving dissidents and criminals alike; and OPSEC — converting bitcoin to euros leaves a trace, and the Vastaamo extortionist used a different wallet per target. GDPR: Ranta stresses it is often misunderstood — recruitment creates a legitimate interest and an applicant cannot demand deletion mid-process; the aim was to bring EU states onto one line, and he would like a globally consistent model, since EU–US data transfer arrangements are struck down and replaced every few years. Corporate guidance: security is a whole rather than a single system (illustrated by a clinic leaving a patient system open); systematic security management is done with the business, which makes conscious decisions about risk, because consequences ultimately show up in revenue. Individual guidance: a password manager with unique random passwords, and two-factor authentication. Three identifiers — email, phone number and national identity number — are public for the victims; the principle is that a secret must be replaceable, but Finland’s identity number cannot be renewed, making reform important yet enormously costly and slow. Strong authentication is monopolised by a few banks, with Estonia cited as the model and the Population Register Centre’s card having failed on card-reader usability. Deepfakes and the inversion of the burden of proof are also discussed. Notification: GDPR requires notice without undue delay, while the recitals acknowledge investigative needs — Ranta argues the data protection authority and the police should issue consistent guidance. The core advice: do not pay the extortionist (referencing Helena Åhman’s interview, the FBI hostage negotiators’ basic rule and the NBI’s position) — payment guarantees nothing and traps the victim in a loop — and do not read the leaked data, since it is a crime and it strengthens the extortionist’s weapon. The episode closes on an aviation analogy: learning from accidents is what made flying safe, and every crisis is an opportunity to improve.