Owen Leigh Optometry Ransomware Claim by DragonForce (Sep 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around 16 September 2026, the DragonForce ransomware group allegedly listed Owen Leigh Optometry, a United Kingdom based eyecare and vision therapy practice, on its dark web leak site. According to the threat actor, the claimed exfiltration totals “Full DATA 400 GB+” taken from the organization’s domain, owenleighoptometry.co.uk.
This claim has NOT been independently verified by Yazoul Security. The listing may be exaggerated, recycled, or entirely fabricated. Ransomware operators frequently inflate data volumes and victim counts to pressure targets into paying. No samples, credentials, download links, or access instructions are reproduced here, in line with our editorial policy.
Threat Actor Profile
dragonforce is a ransomware operation that has historically positioned itself as a “penetration testing” collective, offering affiliates a toolkit and branding under a cartel-style model. Public research on the group is limited, and its total victim count remains unknown. No confirmed toolset has been attributed to this specific campaign.
Based on broader reporting on DragonForce activity, the group has been associated with double extortion tactics, meaning data theft followed by encryption and public shaming. Common intrusion vectors for operations of this type include exposed remote access services, stolen credentials, and exploitation of unpatched edge devices. None of these vectors are confirmed in this case.
Yazoul Security has no YARA rules or detection signatures specific to this incident at the time of writing. Organizations should rely on general ransomware detection guidance, including monitoring for unusual data staging, large outbound transfers, and unauthorized access to backup infrastructure. Our broader detection resources are available at /intel/.
Alleged Data Exposure
The threat actor claims to hold more than 400 GB of data. The nature of that data is unspecified. Given the healthcare and optometry context, plausible categories could include patient records, appointment histories, prescription and clinical notes, staff details, and internal business documents. However, this is speculation based on sector norms, not evidence.
No data samples have been reviewed by Yazoul Security. We cannot confirm the authenticity, scope, or sensitivity of any allegedly stolen material. Claims of this size are often overstated, and some groups pad listings with duplicate or low-value files to appear more threatening.
Potential Impact
If the claim is accurate, potential consequences could include regulatory scrutiny under UK data protection law, patient notification obligations, reputational harm, and operational disruption to clinical services. Optometry practices hold sensitive health information, which raises the stakes of any confirmed breach.
That said, no impact has been confirmed. The practice may have robust backups, may not have experienced encryption, or may dispute the claim entirely. Readers should avoid drawing conclusions until the organization or regulators issue a statement.
What to Watch For
- Official statements from Owen Leigh Optometry or its representatives.
- Notification from the UK Information Commissioner’s Office, if applicable.
- Updates to the leak site, including countdown timers or sample postings.
- Credential-stuffing or phishing activity targeting patients and staff.
- Similar listings from DragonForce against other UK healthcare providers.
Organizations in the healthcare sector should review remote access controls, enforce multi-factor authentication, and validate backup integrity. Our advisory library at /advisory/ covers ransomware readiness in more depth.
Disclaimer
This report is based solely on an unverified claim published by a ransomware group. Yazoul Security has NOT independently confirmed the attack, the data theft, the volume of data, or the involvement of DragonForce. Nothing in this article should be treated as fact. Ransomware groups routinely exaggerate or fabricate claims. Affected parties and the public should await official confirmation before acting on this information.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
REHA-ACTIV — dragonforce
Ramos Rheumatology — dragonforce
AdvancedHEALTH — dragonforce
Advanced Medical Consultants — dragonforce