On 21 October 2020, Psykoterapiakeskus Vastaamo — Finland's largest private psychotherapy provider, a chain of some twenty-five clinics that also took referrals from the public health system — announced that its patient database had been stolen and that an extortionist was demanding 40 bitcoin, then roughly €450,000, against publication. The stolen records were not billing files. They were therapy session notes: what tens of thousands of people, children among them, had told their therapists in confidence. The theft itself was old — investigators traced intrusions to November 2018 and March 2019 — and the chief executive had known of the blackmail since late September. What was new, that Wednesday, was that Finland found out.
The extortionist, posting on a Finnish-language Tor forum as ransom_man, announced he would publish a hundred patients' records every twenty-four hours until he was paid, and began doing so; at one point the entire database briefly appeared online as a single file. When the company did not pay, the demand changed address. Patients began receiving emails directly: €200 in bitcoin within twenty-four hours, €500 after that, or their notes — suicide attempts, abuse, diagnoses — would be published. Tens of thousands of the emails went out. Crisis helplines were reinforced, ministers met in emergency session, and police told recipients not to pay. Within days more than 25,000 people had filed criminal complaints, the beginning of what Finnish authorities came to describe as the country's largest criminal case.
Accountability began inside the company. On 26 October the board dismissed chief executive Ville Tapio, saying he had known of the March 2019 intrusion and concealed it from them for over a year and a half. The government moved to fast-track a law letting victims of serious breaches change their personal identity codes — an admission that ordinary remedies did not fit this harm. None of it saved Vastaamo: in February 2021 the Helsinki District Court declared the company bankrupt. Tapio was convicted in April 2023 of a data-protection offence and handed a three-month suspended sentence; in December 2025 the Helsinki Court of Appeal acquitted him, unanimously, finding the gross negligence required for criminal liability unproven.
The extortionist took longer. In February 2023, French police answering a domestic-disturbance call in Paris found a young Finn living under a false identity: Aleksanteri Kivimäki, once a teenage Lizard Squad hacker. Extradited and tried, he was convicted in April 2024 on nearly thirty thousand counts — extortion, attempted extortion and privacy violations — and sentenced to six years and three months, raised on appeal to six years and eleven months in February 2026. Released from detention while the appeal ran, he did not come back. When Finland's Supreme Court refused his final appeal on 13 July 2026, police issued a wanted notice; his lawyer believed him abroad. The cruellest breach in this archive has, at the time of writing, no one in prison for it.
An increased and imminent threat
October opened with an attempt to prevent exactly what closed it. In its first fortnight, US Cyber Command and then Microsoft — armed with a federal court order — disrupted TrickBot, the botnet that delivered Ryuk ransomware; by 18 October Microsoft counted 120 of 128 servers eliminated, the stated worry being election week. The disruption proved temporary. In the month's final days Ryuk struck American healthcare — Sky Lakes Medical Center in Oregon, the St. Lawrence Health System in New York and, on 28 October, the University of Vermont Health Network — and that same day CISA, the FBI and HHS issued advisory AA20-302A, warning of "an increased and imminent cybercrime threat" to US hospitals. In Burlington, a month after the Universal Health Services shutdown of our September edition, the electronic record system stayed down until 22 November: chemotherapy schedules were lost, some patients were sent to other hospitals, about 300 staff were furloughed or redeployed, and the network's president later put the cost near $1.5 million a day — more than $63 million by early December. No ransom was paid; the hospital said it never contacted the attackers.
Six names from Unit 74455
On 19 October, the US Justice Department unsealed an indictment against six officers of Unit 74455 of Russia's GRU — the group researchers had long called Sandworm — for what prosecutors described as the most disruptive and destructive series of computer attacks ever attributed to a single group: the blackouts inflicted on Ukraine's grid in December 2015 and December 2016, the hack-and-leak operation against France's 2017 election, the NotPetya worm — which the indictment said caused nearly $1 billion in losses to just three American victims — and Olympic Destroyer, which hit the opening ceremony of the 2018 Winter Games. The same day, Britain's NCSC said the GRU had also run reconnaissance against the postponed Tokyo Olympics. "No country has weaponized its cyber capabilities as maliciously or irresponsibly as Russia," said Assistant Attorney General John Demers. The six were named, photographed and charged; none has ever been arrested. Sixteen months later their employer sent tanks into Ukraine, and the unit went back to work against the grid it had twice turned off.
The blackout and the vaccine maker
At about ten on the morning of 12 October, Mumbai lost power. A cascade of tripping that began on the Kalwa–Padgha transmission corridor brought down supply to a city whose islanding scheme is supposed to protect it from India's worst outages: local trains stopped between stations, traffic signals went dark, and hospitals — many of them full of Covid-19 patients — switched to backup generators. Most areas had power back within hours; some waited into the evening. The official explanation was technical failure. Then, in early 2021, the American firm Recorded Future reported that a China-linked group it called RedEcho had placed malware across India's power sector — while saying plainly it could not confirm any link to the outage. Maharashtra's energy minister, citing the state cyber cell's preliminary findings, called the blackout sabotage. The central government answered with two inquiries of its own: human error, no cyber cause established. POSOCO, the national grid operator, said its systems had not been affected.
Ten days after the blackout, on 22 October, Dr Reddy's Laboratories — one of India's largest drugmakers, granted approval five days earlier to run Indian trials of Russia's Sputnik V Covid-19 vaccine — told the stock exchanges it had detected a cyber-attack and had isolated all its data-centre services as a precaution. Press reports described ransomware and plants isolated across several countries; the company said it expected key services back within twenty-four hours and no major impact on operations. Unlike the blackout, nothing here was disputed: the company confirmed the incident itself. Between them, the month put a question this archive keeps reopening: what happens when power grids and vaccine plants become someone else's targets.
No One Behind the Wheel
On 8 October 2020, Waymo opened fully driverless rides — no safety driver, no one behind the wheel — to the public in suburban Phoenix: existing Waymo One riders first, anyone with the app in the weeks that followed, across roughly fifty square miles of Chandler, Tempe and Mesa. Until that week, rides without a human minder had been limited to a small group of early users bound by non-disclosure agreements, a small fraction of the service's trips. It was the first time ordinary passengers could summon a car with an empty driver's seat, and six years on it reads as the founding moment of the robotaxi business rather than a desert curiosity. A week later, at its Search On event on 15 October, Google said the BERT language model — applied to about one English query in ten when it arrived a year earlier — now touched almost every English search, and demonstrated a feature that names a song from a hummed melody: an early sign of search being rebuilt around language models.
McAfee Rings the Bell Again
On 22 October 2020, McAfee began trading on the Nasdaq under the ticker MCFE — a second public life for one of the oldest names in anti-virus, which had traded in its own right until Intel agreed to buy it for about $7.7 billion in 2010, then passed a majority stake to the private-equity firm TPG in 2017. Pitched to investors on a year of pandemic-era growth in consumer security, the offering priced at $20 a share, the company and its backers selling 37 million shares to raise roughly $740 million at a valuation near $8.6 billion. The reception was cool: the stock opened at $18.60 and finished its first day below the offer price. The second listing proved brief. In 2021 McAfee sold its enterprise arm to Symphony Technology Group for $4 billion — the half later folded into Trellix — and that November an investor group led by Advent and Permira agreed to take the consumer remainder private for over $14 billion, completing the purchase in March 2022, less than seventeen months after the opening bell.
⏳ Time capsule — October 2020
- US President Donald Trump announced on 2 October that he had tested positive for Covid-19, and spent three nights at Walter Reed military hospital.
- The Nobel Prize in Chemistry went to Emmanuelle Charpentier and Jennifer Doudna on 7 October for CRISPR-Cas9 gene editing — the first science Nobel won by two women together.
- NASA's OSIRIS-REx spacecraft touched asteroid Bennu on 20 October and collected so much rubble that its sampler head jammed open; the sample reached Earth in 2023.
- Sean Connery, the first cinematic James Bond, died on 31 October, aged 90.
The month extortion got personal
Vastaamo is where this archive's breach coverage stops being about records and starts being about people. The technique it introduced — when the organisation will not pay, extort its customers one by one — recurs through the later years of these pages, from stolen medical files to children's school records. Finland's answers set precedents too: a fast-tracked identity-code law, a bankruptcy that proved a breach can kill a company, a chief executive prosecuted over security and finally acquitted in December 2025, and an investigation that treated tens of thousands of extortion emails as tens of thousands of crimes. The sentence became final on 13 July 2026. The man it belongs to has, at the time of writing, not been found.
The rest of the month set trajectories the decade followed. The hospital wave that AA20-302A warned of ran on through these pages — Ireland's public health service encrypted in May 2021, Change Healthcare stopping the flow of American medical payments in February 2024. TrickBot, rebuilt within weeks of its takedown, folded into the Conti operation, and its members were named, sanctioned and indicted by 2023. The six GRU officers charged on 19 October remain uncaught, and their unit's later work runs through every wartime edition from February 2022 onwards. And the question Mumbai raised — was it the grid, or someone inside the grid? — was never conclusively answered, which is exactly why India's regulators spent the following years demanding faster disclosure.