ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Cyber attack on Asheville Eye Associates impacted close to 200,000 patients

Eye care provider Asheville Eye Associates said a recent cyber attack on its systems compromised the sensitive personal information of almost 200,000 individuals.

 

In a data security incident notice posted on its website, the Asheville, North Carolina-based eye care provider said that it recently detected a cybersecurity incident that impacted its internal network. Asheville Eye immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to contain and remediate the incident and notified relevant law enforcement authorities about the same.

 

While Asheville Eye did not share details about the investigation, it confirmed that the sensitive personal information of its patients was accessed during the incident. The compromised data includes names, addresses, health insurance information and medical treatment data.

 

The eye care provider added that Social Security numbers, credit card numbers and financial information were not exposed during the incident.

 

In a filing with the U.S. Department of Health and Human Services, Asheville Eye said it identified at least 193,306 individuals who were impacted by the data security incident.

 

“AEA takes its responsibility to safeguard personal information seriously and regrets any concern this incident may have caused. As part of AEA’s ongoing commitment to the security of information, the organisation has reviewed and enhanced its data security practices in order to help reduce the likelihood of a similar event in the future,” reads the notice.

 

While Asheville Eye has no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.

 

In December, a group of threat actors calling itself the DragonForce Ransomware group claimed responsibility for the cyber attack on Asheville Eye and listed it as a victim on its data leak site.

 

 

The group claimed to be in possession of 539.46GB of data stolen from the eye care provider and threatened to leak the same unless its ransom demands weren’t met. It is unclear if Asheville Eye negotiated with the ransomware group or paid a ransom.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543