
Eye care provider Asheville Eye Associates said a recent cyber attack on its systems compromised the sensitive personal information of almost 200,000 individuals.
In a data security incident notice posted on its website, the Asheville, North Carolina-based eye care provider said that it recently detected a cybersecurity incident that impacted its internal network. Asheville Eye immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to contain and remediate the incident and notified relevant law enforcement authorities about the same.
While Asheville Eye did not share details about the investigation, it confirmed that the sensitive personal information of its patients was accessed during the incident. The compromised data includes names, addresses, health insurance information and medical treatment data.
The eye care provider added that Social Security numbers, credit card numbers and financial information were not exposed during the incident.
In a filing with the U.S. Department of Health and Human Services, Asheville Eye said it identified at least 193,306 individuals who were impacted by the data security incident.
“AEA takes its responsibility to safeguard personal information seriously and regrets any concern this incident may have caused. As part of AEA’s ongoing commitment to the security of information, the organisation has reviewed and enhanced its data security practices in order to help reduce the likelihood of a similar event in the future,” reads the notice.
While Asheville Eye has no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
In December, a group of threat actors calling itself the DragonForce Ransomware group claimed responsibility for the cyber attack on Asheville Eye and listed it as a victim on its data leak site.
🚨 DragonForce Ransomware Alert 🚨
— FalconFeeds.io (@FalconFeedsio) December 28, 2024
DragonForce ransomware group has added 2 new victims to their dark web portal.
- Asheville Eye Associates 🇺🇸
- IKAV Group 🇩🇪 pic.twitter.com/8fk14G2DKo
The group claimed to be in possession of 539.46GB of data stolen from the eye care provider and threatened to leak the same unless its ransom demands weren’t met. It is unclear if Asheville Eye negotiated with the ransomware group or paid a ransom.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543