Primary Eye Care Data Breach

Alleged

Ransomware claim involving Primary Eye Care.

Published: Aug 6, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Primary Eye Care
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Aug 6, 2026

Executive Summary

Primary Eye Care, a healthcare organization operating in the United States, has been identified as a victim of the DragonForce ransomware group. The listing appeared on the DragonForce dark web portal on August 6, 2026, as observed by SOCRadar’s Dark Web Monitoring service. As an optometry practice, Primary Eye Care handles sensitive patient information and appointment scheduling, systems often managed by third-party vendors, making it a potential target for ransomware attacks. This incident marks one of two listings attributed to DragonForce on that specific date. Over the 60 days preceding this listing, DragonForce claimed approximately 50 other victims. The group predominantly targets sectors such as business services, manufacturing, and hospitality, with a significant concentration of victims located in the United States, the United Kingdom, and the United Arab Emirates. While healthcare is not among DragonForce’s top three targeted industries, the high volume of over fifty claimed victims in two months indicates a broad targeting scope, making the inclusion of a clinical practice like Primary Eye Care consistent with their established pattern rather than a shift in focus. Other recent victims that share similarities with Primary Eye Care include EduSpa, Mike Graham Heating And Air Conditioning, P. A. Inc. (Performance Alloys), and MBM Law.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not return any records associated with the domain primaryeyecareneworleans.com within the queried dataset. It is crucial to understand that a lack of evidence in this specific query does not confirm that the organization remains unaffected. The query was limited to a paginated sample of one dataset. Potential credential exposure could exist under alternate corporate domains, through third-party electronic health record vendor systems, or via personal email aliases utilized on clinic workstations, none of which would be captured by this domain-specific search. Optometry practices often rely on external vendors for practice management and insurance claims processing, which typically operate under separate vendor namespaces that are outside the scope of a domain-based query. For ransomware groups like DragonForce, the harvesting of credentials via infostealers is a recognized initial access vector. Threat actors or initial access brokers frequently acquire recent logs from underground marketplaces. They then validate these corporate credentials to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote access portals, ultimately enabling the deployment of ransomware. The absence of discovered credentials in this particular query does not preclude this possibility; credentials may have been present in other data feeds not queried, rotated by the organization before being indexed, or compromised through personal email addresses. Therefore, cybersecurity intelligence teams should continue monitoring and implementing proactive credential hygiene measures. A null query result should not be interpreted as definitive proof of security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.