Critical Unverified

Smart Eye Care Ransomware Claim by Booba Project (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Claim Summary

On or around September 23, 2026, the ransomware group tracked as Booba Project allegedly listed Smart Eye Care, a healthcare and optometry provider operating at smarteyecare.com, on its dark web leak site. According to the threat actor, the group claims to have stolen approximately 7 GB of data, which it describes as “Optometrists Stolen data.”

This claim has NOT been independently verified by Yazoul Security or any third party. The listing appears on a ransomware group’s leak site, which is an unregulated and frequently unreliable source. Ransomware operators routinely exaggerate data volumes, fabricate samples, or list victims preemptively to pressure negotiations. Nothing in this report should be treated as confirmed fact.

The attack date is listed as September 23, 2026. No country attribution was provided in the leak site entry, and no additional victim details were disclosed.

Threat Actor Profile

Booba Project is a ransomware operation with limited public documentation. As of this writing, there is no established public research available on the group’s tooling, initial access vectors, or affiliate structure. Its total number of known victims is unknown, which makes any credibility assessment difficult.

Because the group’s known tools and tactics are undocumented, we cannot confirm whether Booba Project employs common double extortion techniques, whether it operates a ransomware-as-a-service model, or whether it has a history of publishing data after failed negotiations. Groups with thin public track records sometimes rebrand from prior operations, but no such link has been established here.

Without YARA rules, IOCs, or detection guidance specific to this group, defenders should rely on general ransomware detection practices rather than actor-specific signatures. Any future Yazoul advisory on this group will be published at /advisory/ as tooling becomes known.

Alleged Data Exposure

The threat actor claims to hold 7 GB of data characterized as optometrist-related information. If genuine, healthcare and optometry records could potentially include patient names, contact details, appointment histories, insurance information, or prescription data.

However, several caveats apply. The 7 GB figure is self-reported and unverified. The description “Optometrists Stolen data” is vague and may not reflect the actual contents. Ransomware groups have previously padded archives with junk files or recycled data from unrelated victims to inflate perceived impact.

Yazoul Security has not seen, reviewed, or validated any data samples. We do not publish, link to, or facilitate access to leaked material, and no download links, credentials, or .onion addresses appear in this report.

Potential Impact

If the claim is accurate, a healthcare data exposure of this nature could trigger regulatory obligations under HIPAA and comparable state and international privacy laws. Affected patients could face risks related to identity theft, medical fraud, or targeted phishing.

Operationally, Smart Eye Care could face disruption to scheduling, billing, or electronic health record systems if the intrusion extended beyond data theft. Reputational harm and patient trust erosion are also plausible outcomes, particularly given the sensitivity of eye care and prescription records.

That said, these are potential consequences contingent on the claim being true. Many leak site listings never result in verified breaches, and some victims are listed without any actual data theft occurring.

What to Watch For

  • Official statements from Smart Eye Care or its representatives confirming or denying the incident.
  • Regulatory filings or breach notifications that would corroborate the claim.
  • Whether Booba Project publishes data samples, which would raise confidence in the claim.
  • Any pattern of similar listings by this group that could establish a track record.
  • Updates to our actor profile at /intel/actor/booba-project/ as new information emerges.

Organizations in the healthcare sector should treat this as a reminder to review backup integrity, phishing defenses, and third-party access controls regardless of this specific claim’s validity.

Disclaimer

This report is based entirely on an unverified claim published by a ransomware group on its leak site. Yazoul Security has NOT independently confirmed the breach, the data volume, the data contents, or the involvement of Booba Project. The information here is provided for situational awareness only and should not be relied upon for legal, compliance, or incident response decisions without independent verification. Ransomware groups frequently misrepresent their claims.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.