Healthcare provider · Vision and ophthalmology services · Specialty clinic network · USA
Ophthalmology and eye care practice.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Valley Eye Associates, an ophthalmology/optometry/LASIK practice in Appleton, Wisconsin, suffered a ransomware attack around October 8-9, 2025 attributed to the Qilin group, which exfiltrated roughly 139 GB of data and published it after the ransom went unpaid. The exposed data included names, dates of birth, gender, addresses/zip codes, insurance information, patient IDs, encounter/claim details, and procedure/diagnosis information; the record also lists Social Security numbers. About 44,007 records are recorded (pending an official individual count). The practice reported a data security incident and is notifying affected individuals.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
44K records analyzed
Valley Eye Associates is an ophthalmology, optometry, and LASIK eye-surgery practice based in Appleton, Wisconsin, providing comprehensive vision and eye-surgery care. It maintains patient identity, insurance, billing, appointment, and clinical/ophthalmic treatment records.
Ophthalmology practices collect patient identity, contact, insurance, billing, appointment, and treatment records tied to specialty vision care.
The Qilin ransomware group accessed Valley Eye Associates' network around October 8-9, 2025, exfiltrating roughly 139 GB of data and publishing it after the ransom was not paid. The practice reported a data security incident and began reviewing affected files to notify individuals; class-action investigations followed.
The published Qilin dataset combined identity and clinical data, including names, dates of birth, insurance details, patient IDs, procedures/diagnoses, and government-identification details (and, per the record, Social Security numbers), creating identity-theft, insurance-fraud, and medical-fraud risk. Eye-condition diagnoses (such as glaucoma or macular degeneration) add sensitivity, and the public release of the data raises the likelihood of downstream misuse and targeted scams.
• Identity theft and synthetic identity construction using SSN/government ID and DOB | • Medical identity fraud and insurance abuse using diagnosis, procedure, and insurance data | • Targeted phishing and vishing referencing eye care or claims | • Geographic narrowing/targeting from zip code | • SIM swap attacks where phone numbers are present
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware-as-a-service group also known as Agenda and first observed in 2022. It became one of the more active ransomware groups in 2025, with targeting across healthcare, manufacturing, legal services, critical infrastructure, and public-sector entities.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation