Ocuco breach exposes health data of about 241,000 people

Organization
Ocuco
Exploit
Ransomware
Industry
Healthcare Technology

Ocuco, a Dublin based supplier of practice management and laboratory software to optical retailers, eye hospitals and optical labs, reported a network server hacking incident to the U.S. Department of Health and Human Services Office for Civil Rights on May 30, 2025. The filing listed 240,961 affected individuals.

Ocuco said an attacker reached two of its non-production servers in late March 2025 by exploiting a newly discovered flaw in third-party software that, according to the company, had not been disclosed in time for it to patch. Ocuco said it learned of the compromise on April 1 after the intruder's claims surfaced publicly.

The ransomware-as-a-service group KillSec listed Ocuco on its dark web leak site the same day, claiming roughly 670,000 files totalling about 340 gigabytes. SecurityWeek reported that no Ocuco files were actually available for download from the leak site at the time of its review. HIPAA Journal reported that the stolen data was subsequently listed for download, which it said suggests the ransom was not paid.

Ocuco said the exposed files could contain names alongside addresses, Social Security numbers, health insurance and medical record numbers, provider names, prescriptions, diagnoses, treatment information, lab results and medical histories. The company patched the vulnerability, reviewed its security controls, and issued a substitute breach notice on July 14, 2025 saying it was not aware of any misuse of the data.

Sources