Optical Software Solution Provider Ocuco Inc., based in Dublin, Ireland, has reported a data breach affecting 240,961 individuals. The incident, listed as a network server hacking incident, involved a ransomware attack by Killsec, claiming to be a hacktivist group. The breach exposed protected health information, including business files, appointment information, and data from U.S. and Canadian eyecare clients like Costco, HoustonEye, Kaiser, Mayo Clinic, Optos, Specsavers, and more. Several law firms have opened investigations into potential class action lawsuits.
Source: https://www.hipaajournal.com/ocuco-data-breach/
TPRM report: https://scoringcyber.rankiteo.com/company/ocuco
"id": "ocu642061725",
"linkid": "ocuco",
"type": "Ransomware",
"date": "6/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '240,961 individuals',
'industry': 'Optical Software Solutions',
'location': 'Dublin, Ireland',
'name': 'Ocuco Inc.',
'type': 'Company'}],
'attack_vector': 'Network Server Hacking',
'data_breach': {'data_exfiltration': 'Yes',
'file_types_exposed': ['Business files',
'Appointment information'],
'number_of_records_exposed': '240,961',
'type_of_data_compromised': 'Protected Health Information'},
'date_publicly_disclosed': '2025-05-30',
'description': 'Ocuco Inc., a Dublin, Ireland-based provider of optical '
'software solutions for eyecare businesses, has recently '
'notified the HHS’ Office for Civil Rights about a data breach '
'involving the protected health information of 240,961 '
'individuals.',
'impact': {'data_compromised': 'Protected Health Information',
'legal_liabilities': 'Potential class action lawsuits'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
'investigation_status': 'Ongoing',
'motivation': 'Financial',
'ransomware': {'data_exfiltration': 'Yes',
'ransom_paid': 'No',
'ransomware_strain': 'Killsec'},
'references': [{'source': 'HIPAA Journal'}],
'regulatory_compliance': {'regulatory_notifications': 'HHS’ Office for Civil '
'Rights'},
'threat_actor': 'Killsec (Kill Security)',
'title': 'Optical Software Solution Provider Ocuco Reports 241K-Record Data '
'Breach',
'type': 'Data Breach'}