{"id":10205,"date":"2024-01-29T11:42:15","date_gmt":"2024-01-29T09:42:15","guid":{"rendered":"https:\/\/forklog.com\/en\/finnish-authorities-track-monero-using-hacker\/"},"modified":"2024-01-29T11:42:15","modified_gmt":"2024-01-29T09:42:15","slug":"finnish-authorities-track-monero-using-hacker","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/finnish-authorities-track-monero-using-hacker\/","title":{"rendered":"Finnish Authorities Track Monero-Using Hacker"},"content":{"rendered":"<p>Finland&#8217;s National Bureau of Investigation (KRP) has traced transactions involving the anonymous cryptocurrency Monero (XMR) linked to hacker Julius Kivim\u00e4ki, according to local <a href=\"https:\/\/www.mtvuutiset.fi\/artikkeli\/vastaamo-jutussa-iso-paljastus-krp-jaljitti-jaljittamattomana-pidettya-kryptovaluuttaa\/8864046#gs.46q5e9\">media<\/a>.\u00a0<\/p>\n<p>On January 22, the prosecution presented new evidence indicating illegal transfers leading to Kivim\u00e4ki&#8217;s bank account.\u00a0<\/p>\n<p>Investigators allege that in 2020, the suspect demanded 40 BTC to avoid publishing personal data of over 33,000 patients from the Vastaamo psychotherapy center. The hacker operated under the pseudonym ransom_man.\u00a0<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-eu.googleusercontent.com\/fWR4m9a65qMLAiSnoW1LlCQ2D4r69pGP9gNzdyglFUqmUOYno7uguRlog6Dtt5YSoPEu8LQTnsYzEjsF-DZw_qXLWYIHevFjRr3WoO8kZGNqkKkKiWKUXPN9lFMWMVs8MEMaKohf1HlH_ZMoiDZ8KwY\" alt=\"Finnish Authorities Track Monero-Using Hacker\"\/><figcaption class=\"wp-element-caption\">The hacker&#8217;s demand letter. Source: <a href=\"https:\/\/krebsonsecurity.com\/2022\/11\/hacker-charged-with-extorting-online-psychotherapy-service\/\">KrebsOnSecurity<\/a>.<\/figcaption><\/figure>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe are not asking for much, about \u20ac450,000, which is less than \u20ac10 per patient and only a small part of the company&#8217;s \u20ac20 million annual revenue,\u201d stated ransom_man.<\/p>\n<\/blockquote>\n<p>On October 23, 2020, the hacker uploaded a large file containing all the stolen Vastaamo records to the darknet. However, investigators found that the data also included a complete copy of ransom_man&#8217;s personal folder\u2014a critical mistake that linked the evidence to Kivim\u00e4ki.<\/p>\n<p>Eventually, the leaked files were removed, accompanied by the note \u201coops.\u201d However, other users, and consequently law enforcement, managed to download them. Unknown individuals created a separate website with the entire patient database of the clinic.\u00a0<\/p>\n<p>Some victims paid the ransom, but once the leaked data was found online, the blackmail lost its power.\u00a0<\/p>\n<p>KRP discovered that the hacker sent assets to an exchange that did not comply with <span data-descr=\"know your customer\" class=\"old_tooltip\">KYC<\/span> requirements. He then exchanged bitcoins for Monero and transferred them to a personal wallet.\u00a0<\/p>\n<p>After several manipulations, XMR was sent to a Binance account, where it was exchanged back into the primary cryptocurrency. The coins were then moved to various wallets.\u00a0<\/p>\n<p>Authorities have not disclosed the methodology used to analyze the transactions. Ultimately, the investigation traced Kivim\u00e4ki through his X account. In October 2022, the hacker was charged with criminal offenses.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"fi\" dir=\"ltr\">Uskon ett\u00e4 KRP toi t\u00e4m\u00e4n nyt julkisuuteen vaikuttaakseen juuri hovioikeudessa k\u00e4sitellyn vanhan teinivuosien juttuni p\u00e4\u00e4t\u00f6ksentekoon, molemmissa jutuissa on samat henkil\u00f6t tutkimassa.<a href=\"https:\/\/t.co\/mlqGfJoda9\">https:\/\/t.co\/mlqGfJoda9<\/a><\/p>\n<p>\u2014 Aleksanteri Kivimaki (@AlexKivimaeki) <a href=\"https:\/\/twitter.com\/AlexKivimaeki\/status\/1586083493641351168?ref_src=twsrc%5Etfw\">October 28, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cI believe that KRP brought this to public attention to influence the decision-making on my old teenage case, which was just heard in the appeals court\u2014both are being investigated by the same people,\u201d wrote Kivim\u00e4ki.\u00a0<\/p>\n<\/blockquote>\n<p>It was revealed that at the age of 17, the suspect was convicted of stealing classified data from the U.S. Air Force and hacking the American Airlines website. He was sentenced to one year of probation for fraud and theft of confidential data.\u00a0<\/p>\n<p>The prosecution is now seeking a real prison term for Kivim\u00e4ki.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Interesting day in Finland. <a href=\"https:\/\/twitter.com\/hashtag\/vastaamo?src=hash&#038;ref_src=twsrc%5Etfw\">#vastaamo<\/a> <a href=\"https:\/\/t.co\/FupGQ9fWWE\">pic.twitter.com\/FupGQ9fWWE<\/a><\/p>\n<p>\u2014 Joe Tidy (@joetidy) <a href=\"https:\/\/twitter.com\/joetidy\/status\/1748388591598760389?ref_src=twsrc%5Etfw\">January 19, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cThe young man committed cybercrimes from [the Finnish city of] Espoo from the age of 15, and these actions had to be thoroughly investigated with international legal support,\u201d <a href=\"https:\/\/www.is.fi\/digitoday\/art-2000009041118.html\">stated<\/a> the prosecution.\u00a0<\/p>\n<\/blockquote>\n<p>Authorities also raised concerns against Vastaamo&#8217;s head, Ville Tapio, for violations of personal data security requirements. He resigned immediately after the attack.\u00a0<\/p>\n<p>The leak could have occurred as early as 2018, and Tapio allegedly concealed the incident for nearly a year and a half.\u00a0<\/p>\n<p>Former MAGIC Monero Fund committee member Chilla Brimer commented to <a href=\"https:\/\/decrypt.co\/214367\/did-law-enforcement-crack-privacy-coin-monero-its-complicated\">Decrypt<\/a> that investigators likely managed to trace some transactions due to the hacker&#8217;s poor security practices, rather than a breach of the Monero network itself.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cIf you are not careful with your operational security and continue switching between Bitcoin and XMR, there is a risk of leaking some information. Regulators may use this mistake to claim Monero tracking,\u201d she explained.<\/p>\n<\/blockquote>\n<p>According to Brimer, Monero \u201csecurely protects transaction details,\u201d but cannot save users from their own mistakes.\u00a0<\/p>\n<p>In January 2024, Binance <a href=\"https:\/\/u1f987.com\/en\/news\/binance-labels-zcash-and-monero-as-high-risk-assets\">classified<\/a> Monero and Zcash as high-risk crypto assets, assigning them \u201cmonitoring tags.\u201d\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Finland&#8217;s National Bureau of Investigation (KRP) has traced transactions involving the anonymous cryptocurrency Monero (XMR) linked to hacker Julius Kivim\u00e4ki, according to local media.\u00a0 On January 22, the prosecution presented new evidence indicating illegal transfers leading to Kivim\u00e4ki&#8217;s bank account.\u00a0 Investigators allege that in 2020, the suspect demanded 40 BTC to avoid publishing personal data [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":10204,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[44,513,1150],"class_list":["post-10205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybercrime","tag-monero","tag-news-plus"],"aioseo_notices":[],"amp_enabled":true,"views":"141","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/10205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=10205"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/10205\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/10204"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=10205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=10205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=10205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}