Quick Summary
AllegedExecutive Summary
Booba Project ransomware has targeted Smart Eye Care, a provider within the optometry and vision care sector. The threat actor listed the company on its dark web portal on September 23, 2026, a development identified through SOCRadar’s Dark Web Monitoring services. The threat actor indicated that healthcare data was compromised. Smart Eye Care was listed alongside other organizations including Washington County, The Merrimack County, and COSEF in a batch publication by the ransomware group. This incident places Smart Eye Care within the context of Booba Project’s recent activity. Over the preceding 60 days, the group has claimed responsibility for the data compromise of 14 other entities. Their most frequently targeted industries include Professional Services, Government & Defense, and Technology. The inclusion of a Healthcare organization like Smart Eye Care is considered atypical for Booba Project’s usual modus operandi. The primary geographic focus for Booba Project’s victims has been the United States, with additional victims noted in Italy and Moldova. This pattern suggests an opportunistic approach to targeting rather than a specific campaign focused on the healthcare sector.
Technical Analysis
SOCRadar’s investigation included a query for the domain smarteyecare[.]com, which returned one record. This record indicated the exposure of a corporate email address associated with @smarteyecare.com on MyHeritage, a consumer genealogy platform. The classification of this finding points to a workstation-level compromise rather than direct access to organizational portals. It is assessed that an employee’s device was infected with an infostealer, which subsequently captured browser-stored credentials across both personal and work accounts. Critically, no internal system credentials for smarteyecare[.]com were found within this particular sample. The exposure of an employee’s corporate email address, even if originating from a personal platform like MyHeritage due to shared credentials or infostealer activity, does not rule out potential initial access pathways for threat actors. While the specific query did not reveal internal system credentials linked to the smarteyecare[.]com domain, the presence of an infostealer compromise on an employee workstation highlights a significant risk. Such compromises can lead to the exfiltration of sensitive information, including session cookies and saved credentials, which could potentially be leveraged for further network lateral movement or the deployment of ransomware, especially if other corporate credentials exist on the compromised device. Recommended Actions: Credential rotation for the identified employee account should be performed immediately. An audit of endpoint hygiene on the affected device is also recommended. Ongoing monitoring of corporate email aliases against future third-party breach datasets is advised. Furthermore, ensuring Multi-Factor Authentication (MFA) is enforced on all corporate applications is a critical step to bolster security posture.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.