FYIdoctors Listed by cactus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The FYIdoctors Listed by cactus Ransomware Group (reported November 28, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to single out healthcare and clinical networks because the data they hold is both sensitive and operationally critical, creating pressure to respond quickly. In that landscape, the appearance of a major Canadian eye-care provider on a ransomware leak site is a familiar pattern: an organisation is named, files are claimed to have been taken, and the public is left to assess the risk with limited official detail.
On 28 November 2023, FYIdoctors was listed by the cactus ransomware group. Public reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected has not been disclosed, and fuller technical particulars remain limited. For patients and staff, the listing itself is reason enough to understand what is known, what is claimed, and what practical steps follow.
Breaking down the breach
According to available reporting, FYIdoctors was listed by the cactus ransomware group on 28 November 2023. The incident is characterised as a ransomware attack in which internal files were allegedly exfiltrated. No confirmed figure has been published for the number of individuals affected, and public detail does not specify the precise intrusion method, the duration of unauthorised access, or a full inventory of systems involved.
What is stated is that internal files were taken as part of the attack. Beyond that description, the scale of the exposure, the exact file categories, and any subsequent confirmation or negotiation outcome are not detailed in the material available. The leak-site listing should be treated as a claim by the group rather than as independently verified proof of every asserted detail. Organisations in this position often investigate and notify regulators or affected parties on their own timeline; those steps, if they occurred, are not part of the public summary provided here.
Who is cactus?
Cactus is a ransomware operation that has been active in the threat landscape in recent years. Like other groups in this category, it is publicly associated with double-extortion tactics: encrypting systems to disrupt operations while also copying data and threatening to publish or sell it if demands are not met. The group has been observed using leak sites to name victims and, in some cases, to stage samples or larger dumps of stolen material as pressure.
Public reporting on cactus generally describes a professionalised criminal enterprise rather than a single individual—affiliates or operators who gain access, move laterally, exfiltrate data, and deploy ransomware. Specific claims the group makes about any one victim, including FYIdoctors, should be read as assertions from the actors themselves unless corroborated by the victim or by independent investigation. No additional statements attributed to cactus about this particular incident beyond the listing and the description of internal-file exfiltration are included in the facts at hand.
About FYIdoctors
FYIdoctors describes itself as having started in 2008 as a small group of independent optometrists in Alberta, focused on personalised care. It has grown into what it calls Canada’s largest eye-care provider, with more than 300 clinics across the country. The organisation operates in the clinical eye-care sector—optometry and related services—where patient relationships, appointment systems, and clinical records are central to daily work.
Entities of this type typically hold identity and contact information, insurance or billing details, appointment histories, and clinical notes related to vision care. A breach affecting such a provider is consequential because the data can be long-lived and personally identifying, and because disruption to clinic systems can affect scheduling and continuity of care. The organisation’s national footprint means any confirmed exposure could touch patients and staff in multiple provinces, even when exact counts remain unknown.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether those files included patient charts, employee records, financial documents, or operational data—has been publicly itemised in the material provided. The number of people affected is unknown.
Organisations in eye care commonly maintain patient demographics, health-card or insurance identifiers, clinical findings, prescriptions, and administrative correspondence, as well as internal business files. It is reasonable to expect that “internal files” could overlap with some of those categories, but it is not established as fact which specific types left the organisation’s control. Exact contents remain unconfirmed; readers should not assume a particular data element was or was not included without official notice from FYIdoctors or regulators.
What's at stake
For individuals, the primary risks are misuse of personal or clinical information if it was among the taken files—identity fraud, targeted phishing that references real appointments or providers, or exposure of health-related details that people expect to remain private. Even when clinical depth is limited, contact and identity data can be reused in social-engineering attempts. Because the affected population size is undisclosed, people who have been patients or employees cannot yet rule themselves in or out solely from public reporting.
For the organisation, stakes include operational disruption from ransomware, regulatory and notification obligations, reputational harm, and the cost of investigation and remediation. Healthcare-adjacent providers also face heightened expectations around safeguarding health information. None of this establishes negligence as a proven fact; it describes the ordinary consequences that follow when a ransomware group claims to have exfiltrated internal material from a large clinic network.
What to do if you're exposed
If you have been a patient or staff member at FYIdoctors, treat the incident as a prompt to tighten routine protections rather than as confirmed proof that your file was taken. Watch for unexpected messages that reference eye care, billing, or personal details; verify any request through official clinic channels rather than links or numbers in an unsolicited email or text. Consider placing fraud alerts or credit monitoring if you later receive formal notice that identity or financial data was involved. Change passwords on accounts that reused credentials tied to clinic portals, and enable multi-factor authentication where available.
Keep any official notification from the organisation; it will be more specific than general public summaries. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritise further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
gdi.com Listed by cactus Ransomware Groupconcordegroup.ca Listed by cactus Ransomware GroupPetersen Health Care Listed by cactus Ransomware GroupMEDIMARKET Listed by cactus Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the FYIdoctors Listed by cactus Ransomware Group →
Publicly posted by cactus — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.