SYS::ONLINE
Wasteland.
Briefs2264
Issues25
SinceFeb 2026
LIVE
█ Ransomware EYECARE-CENTER-SNO 2026-08-26

Eyecare Center of Snohomish: TheGentlemen Ransomware and Patient Data Theft

"Eyecare Center of Snohomish, an optometry practice serving Snohomish County, Washington since 1964, has been named on the dark web leak site of the ransomware group TheGentlemen. Trackers and threat intelligence vendors…"

Eyecare Center of Snohomish, an optometry practice serving Snohomish County, Washington since 1964, has been named on the dark web leak site of the ransomware group TheGentlemen. Trackers and threat intelligence vendors logged the listing on August 23, 2026, with an estimated intrusion date of August 21, 2026, and notification activity reported in August 2026. No victim count has been published, no regulator filing has surfaced publicly, and none of the available sources reproduce a statement in the clinic's own words. Every source consulted for this brief is third-party tier: leak site trackers, breach-monitoring vendors, and consumer-facing breach explainers. Nothing here carries a primary confirmation, and the brief is written accordingly.

What Happened

The core facts are consistent across the trackers. TheGentlemen posted Eyecare Center of Snohomish to its extortion site, with the clinic's domain, eyecarecenterofsnohomish.com, as the identified entity. Ransomware.live and HookPhish both record a discovery timestamp of 2026-08-23 06:34 UTC and an estimated attack date of 2026-08-21. QPulse, which draws from the Ransomware.live feed, repeats those same timestamps. SOCRadar independently dates the leak site listing to August 23, 2026, and CyberThreatIntelligence.net gives the same disclosure date.

Breachsense is the outlier, dating the breach to August 22, 2026 and the discovery to August 22, 2026. That is a one-day discrepancy against five other trackers and most likely reflects a different indexing pass rather than a separate event. Readers should treat August 21 to August 23, 2026 as the window rather than fixing on a single day.

The more important divergence is about status. DataBreachRights describes the incident as "confirmed" by the practice and states that the clinic disclosed it publicly in August 2026. SOCRadar labels the same incident "Alleged." QPulse frames it as a claim by the group. On the current record, the only thing independently verifiable is that TheGentlemen claimed the clinic. DataBreachRights is the sole source asserting victim confirmation and issued notifications, and it provides no letter, no filing reference, and no quote to support that. We report it as that outlet's claim, not as established fact.

DataBreachRights also concedes in its own text that the intrusion start date, the full forensic timeline, and the entry vector have not been publicly disclosed, and it hedges heavily on the clinic's response steps. Its narrative sections read as pattern-based inference about how ransomware cases typically unfold rather than reporting on this one.

What Was Taken

Nobody has published a number. Ransomware.live lists the leak size as unknown. Breachsense lists leak size as unknown. SOCRadar, QPulse and CyberThreatIntelligence.net offer no volume figure. QPulse states explicitly that its source provides no detail on the volume of data potentially compromised, the systems impacted, or the attack vector. There is no record count to report and readers should be skeptical of any outlet that produces one without sourcing.

DataBreachRights publishes the only itemized data inventory in the source set: patient names and contact information, dates of birth, medical and vision treatment records, health insurance information, appointment and billing history, and Social Security numbers. That same page lists "People Affected" as not publicly disclosed and "Regulators Notified" as not publicly disclosed, which is difficult to square with a detailed field-level inventory. Absent a notification letter or a HHS Office for Civil Rights portal entry to check it against, that list should be read as a plausible profile of what an optometry practice holds rather than a confirmed exfiltration manifest.

What can be stated without stretching: an optometry clinic operating continuously since 1964, offering medical eye exams, disease diagnosis and treatment, contact lens fitting and an optical retail operation, necessarily holds protected health information, insurance identifiers and billing records. QPulse identifies the exfiltration and publication of sensitive patient medical data as the primary concern. That is the correct framing given what is actually known.

Why It Matters

This is a small community practice, and that is the point. SOCRadar's profiling puts TheGentlemen at roughly 227 claimed victims in the preceding 60 days, with the United States as the most-targeted country and manufacturing, technology and "other" as the leading sectors. Healthcare is not the group's primary vertical. SOCRadar reads this incident as opportunistic, consistent with a pattern of hitting small and medium enterprises with weaker security postures across whatever sectors present an opening.

Total victim figures for the group vary widely depending on the counting method, and the discrepancies are worth noting rather than smoothing over. CyberThreatIntelligence.net's page carries three different numbers in the same record: a headline count of 789 total victims, a statement that the group has listed 723 victims since February 2023, and a group profile describing emergence in July to August 2025 with over 320 victims across 17-plus countries. That last figure also references a compromised command-and-control server in 2026 that reportedly exposed more than 1,570 linked victims, a figure far above any public leak site tally. The February 2023 start date sits awkwardly against the mid-2025 emergence date given a few lines earlier on the same page. Take the direction of travel, which is high volume and accelerating, and discount the precision.

For defenders, the operational lesson is that a five-clinician optometry office in a town of 10,000 is inside the target set of a ransomware-as-a-service operation clearing hundreds of victims a quarter. Affiliate economics, reported by CyberThreatIntelligence.net as a 90 percent revenue share, reward volume over selectivity. Small healthcare providers that assume obscurity is protection are working from a broken model.

The Attack Technique

No source identifies the initial access vector for this specific intrusion. QPulse states plainly that no CVE IDs were identified in relation to the incident. There is no forensic account in the public record.

What is documented is the group's general tradecraft. CyberThreatIntelligence.net maps TheGentlemen to MITRE ATT&CK T1078, Valid Accounts, describing abuse of legitimate credentials for initial access, persistence, privilege escalation and defense evasion, specifically against externally reachable services such as VPNs, Outlook Web Access, network devices and RDP. The same profile describes a Go-based locker with builds for Windows, Linux, NAS and BSD targets, which indicates an operation prepared to encrypt across mixed environments rather than a Windows-only smash and grab.

SOCRadar ran stealer-log telemetry against eyecarecenterofsnohomish.com and found no direct records in the queried dataset, while explicitly cautioning that a null result in a paginated sample does not rule out compromise. Alternate corporate domains, personal email aliases used for work accounts, and credentials rotated before indexing would all fall outside that query. SOCRadar notes that infostealer-harvested credentials are a significant entry vector for ransomware operations generally.

Breachsense reports one indexed @eyecarecenterofsnohomish.com address appearing in external combo lists, most recently October 27, 2025, and states directly that this is not necessarily connected to the ransomware attack. Two vendors, two different credential-exposure readings, neither establishing a link to this intrusion. Treat credential abuse as the group's documented pattern, not as this case's confirmed cause.

Ransomware.live's DNS enumeration shows the clinic on Google Workspace mail with a Squarespace-registered domain and no well-known cloud or SaaS platforms detected. That is a typical small-practice footprint: a hosted email tenant, a website vendor, and a practice management system almost certainly running on premises or through a specialty vendor. It offers no evidence about the intrusion path, but it does describe the surface a defender would need to cover.

What Organizations Should Do

Small healthcare providers should treat this listing as a prompt to close the specific gaps TheGentlemen is documented to exploit.

  1. Enforce phishing-resistant MFA on every externally reachable service, prioritizing VPN, remote desktop, webmail and any practice management portal. T1078 is the group's documented entry pattern, and single-factor remote access is the failure mode it depends on.
  2. Audit and rotate credentials for all administrative and remote access accounts, and monitor infostealer log feeds for your domain and for personal addresses staff use with work systems. Both SOCRadar and Breachsense flag the limits of any single telemetry set, so check more than one.
  3. Deploy egress monitoring and alerting on bulk outbound transfers. TheGentlemen exfiltrates before encrypting; the theft window is where detection is still worth something, and by the time the locker runs the leverage is already gone.
  4. Verify that backups are offline or immutable and, more importantly, that a restore has been tested end to end within the last quarter. A Go-based locker built for Windows, Linux, NAS and BSD is explicitly designed to reach the network attached storage where small practices park their backups.
  5. Segment clinical and practice management systems from general office IT so that a compromised workstation does not grant a path to the patient record database.
  6. Have the HIPAA breach notification path mapped in advance, including the 60-day clock, HHS Office for Civil Rights reporting thresholds, and Washington state breach notification requirements. The reputational damage in these cases is driven less by the intrusion than by a slow or vague disclosure.

For patients of the practice, the standing advice from DataBreachRights holds regardless of what the final scope turns out to be: watch for a notification letter, monitor credit reports, and place a credit freeze rather than relying on monitoring alone. If Social Security numbers were in scope, a freeze is the only control that actually blocks new-account fraud.

Sources: Eyecare Center of Snohomish Data Breach Explained | Eyecare Center of Snohomish Data Breach Healthcare | Eyecare Center of Snohomish Ransomware Attack by Thegentlemen (2026... | Ransomware Group thegentlemen Hits: Eyecare Center of Snohomish | Ransomware.live - Victim: Eyecare Center of Snohomish | Thegentlemen Ransomware Group Targets Eyecare Center of Snohomish... | Eyecare Center of Snohomish Data Breach in 2026 Breachsense