Owen Leigh Optometry Data Breach

Alleged

Ransomware claim involving Owen Leigh Optometry

Published: Sep 16, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Owen Leigh Optometry
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Sep 16, 2026

Executive Summary

DragonForce ransomware has listed Owen Leigh Optometry, an independent optometry practice based in the United Kingdom, as a victim. The listing was observed by SOCRadar Dark Web Monitoring on September 16, 2026. The domain associated with the victim is owenleighoptometry[.]co[.]uk. This incident is classified as a listing on a ransomware leak site and does not constitute a confirmed breach. The nature of the business, operating as an independent healthcare provider, may attract opportunistic cybercriminal activity due to potentially limited security resources. DragonForce has claimed approximately 26 victims in the past 60 days, with a notable focus on the ‘Other’ sector, Manufacturing, and Professional Services. The group primarily targets organizations in the United States, the United Kingdom, and Brazil. Previous UK-based victims listed by DragonForce include QPC Global and Lamont Pridmore. In the healthcare sector, Primary Eye Care in the US was also listed. Owen Leigh Optometry aligns with DragonForce’s observed targeting patterns in the UK and the broader healthcare industry.

Technical Analysis

SOCRadar’s analysis of the stealer-log dataset returned no credentials associated with the domain owenleighoptometry[.]co[.]uk. This negative result does not confirm that the organization is unaffected by credential compromise. It is important to note that such findings are not definitive exonerations, as credentials may exist within external data feeds not covered by this specific query. Furthermore, compromised credentials might be held under alternate corporate domains or through personal email aliases used by staff members, which would not be captured by a query limited to the primary corporate domain. The DragonForce ransomware group typically leverages stolen credentials as an initial access vector. Their standard operating procedure involves validating these credentials against common corporate services such as Microsoft 365 or VPNs. Once authenticated, they proceed with the deployment of their ransomware. The absence of direct stealer-log evidence for Owen Leigh Optometry does not rule out the possibility of such an attack path being exploited. This situation underscores the importance of continuous monitoring and proactive security measures. Organizations are advised to maintain vigilance regarding potential credential exposure on the dark web, conduct regular credential hygiene checks, and ensure robust implementation of multi-factor authentication across all critical systems, including Microsoft 365 and remote access portals. Reviewing VPN and other remote access logs for suspicious activity is also recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.