CSIDB logo
Incident

Oceansview Optical

Incident posture

Attack window
Jun 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Oceansview Optical
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Oceansview Optical experienced a ransomware attack that encrypted portions of its database and corrupted external hard drives and backup servers, forcing a temporary shift to paper records during system restoration. The organization did not pay the ransom and could not recover encrypted data spanning over a year due to inaccessible backups, though a copy was retained for potential future decryption. While the primary intent appeared to be data disruption rather than theft, exfiltration of sensitive patient information—including names, contact details, insurance data, medical diagnoses, prescriptions, and eyewear orders—could not be definitively ruled out.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 8, 2022, Oceansview Optical in Sebastian, FL, detected a ransomware attack when its office software abruptly shut down. An investigation confirmed that portions of its database had been encrypted using Venus ransomware. The attack corrupted two external hard drives and the backup server, eliminating immediate options for data restoration. This forced the practice to operate using paper charts for nine days while systems were rebuilt. Oceansview Optical did not pay the ransom demand. Without functional backups, encrypted data spanning from July 2021 to October 8, 2022, remained inaccessible. A copy of the encrypted database was preserved in hopes that a future decryptor for Venus ransomware might enable recovery.

Jennifer L Loar OD, representing Oceansview Optical, stated the primary intent of the attack appeared to be data corruption to disrupt operations, though data exfiltration could not be definitively ruled out. The compromised database contained patient names, nicknames, addresses, phone numbers, email addresses, birth dates, ethnicity, preferred language, insurance details, diagnoses, medications, medication allergies, medical reports, and eyeglass and contact lens orders. No specific evidence confirmed data theft occurred. The incident necessitated a temporary return to manual record-keeping during system restoration, impacting operational continuity. Oceansview Optical retained the encrypted data for potential future decryption but did not disclose whether external cybersecurity support was engaged or if regulatory authorities were notified.

Sources

Sources available to members: 1 source.

CSIDB