Modern Eyez Listed by nokoyawa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Modern Eyez Listed by nokoyawa Ransomware Group (reported July 29, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On July 29, 2023, the optometric practice Modern Eyez was listed by the ransomware group nokoyawa, which claimed to have carried out an attack involving the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no fuller technical account of the intrusion has been released. For patients and staff connected to a vision-care provider in the Rio Rancho area, the listing raises concrete questions about what information may have left the organisation’s systems and what steps are warranted next.
Ransomware incidents of this type typically combine encryption of systems with theft of data used as leverage. In this case the only confirmed public claim is the group’s own listing and the description of internal files as having been taken. Nothing further about timing, method, or confirmed impact has been established in the available record.
What happened
According to the public report dated July 29, 2023, Modern Eyez appeared on a leak site associated with the nokoyawa ransomware group. The group claims that internal files were exfiltrated in a ransomware attack. No independent confirmation of the intrusion, no disclosure of how access was obtained, and no statement of the volume or precise categories of material taken have been made available in the facts at hand. The number of individuals whose information may be involved is listed as unknown. Beyond the leak-site claim itself, operational details—date of initial access, duration of presence in the network, ransom demand, or any negotiation—remain undisclosed.
Who is nokoyawa?
Nokoyawa is a ransomware operation that has been observed in public reporting since roughly 2022. Like many contemporary ransomware groups, it has commonly employed a double-extortion model: encrypting victim systems while also copying data and threatening to publish or sell it if payment is not made. The group has typically targeted organisations across multiple sectors rather than specialising in a single industry, and its leak sites have been used to name alleged victims and, in some cases, to release sample files as proof of theft. Tactics associated with such groups frequently include exploitation of exposed remote-access services, stolen credentials, or unpatched vulnerabilities, followed by lateral movement and data staging before encryption. These patterns are drawn from the broader public record of the actor’s activity and should not be read as confirmed specifics of the Modern Eyez incident. With respect to this listing, the sole assertion on record is the group’s claim that Modern Eyez was hit and that internal files were taken; that claim has not been independently verified in the material provided.
Modern Eyez and its sector
Modern Eyez is described in its own public materials as a provider of vision-care products and personalised optometric services operating since 2003 in Rio Rancho and surrounding areas. The practice offers comprehensive vision examinations and related diagnostic and treatment services. Organisations of this kind sit at the intersection of healthcare and retail: they maintain clinical records, appointment and billing information, and often payment and insurance data for patients, as well as internal administrative files concerning staff and operations.
A breach affecting an optometric practice is consequential because vision-care providers routinely handle protected health information and personally identifiable details. Even when the exact scope of an incident is unclear, the sector’s data holdings mean that unauthorised access can create lasting exposure for patients and operational disruption for the practice itself. Public detail does not establish negligence or specific security failures at Modern Eyez; it simply records that the organisation was named by a ransomware group.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of whether clinical, financial, or employee data were included have been published. Exact contents therefore remain unconfirmed.
Organisations providing optometric care typically hold patient demographics, examination notes, prescriptions, insurance and billing records, appointment histories, and internal business documents such as staffing or vendor information. Any of these categories could theoretically be present among “internal files,” but that possibility is not the same as verified exposure. Until a fuller disclosure or independent analysis appears, it is accurate only to say that internal material was claimed to have been taken and that the precise data types and volume are undisclosed.
Why it matters
For individuals who have been patients or employees of Modern Eyez, the practical risk is that personal or health-related information could surface in criminal markets or be misused for fraud, identity theft, or targeted phishing. Even limited internal files can contain enough identifiers—names, addresses, dates of birth, insurance numbers, or clinical notes—to enable follow-on harm. Because the number of people affected is unknown and the data types are not itemised, the scale of that risk cannot yet be measured; the absence of detail itself is a source of uncertainty for those who may be involved.
For the organisation, a ransomware incident that includes data theft can mean operational downtime, recovery costs, regulatory notification obligations under health-privacy rules, and erosion of patient trust. These consequences follow from the nature of the claimed attack rather than from any adjudicated finding of fault. The listing by nokoyawa is a claim that requires monitoring; it does not by itself prove the full extent of compromise.
If your data was in this claimed breach
If you have been a patient or staff member of Modern Eyez, treat the possibility of exposure seriously while recognising that confirmation is still limited. Monitor financial and insurance statements for unfamiliar activity, be cautious of unexpected messages that reference eye-care appointments or billing, and consider placing fraud alerts with major credit bureaus if you believe sensitive identifiers may have been involved. Retain any breach notification you later receive from the practice, as it may contain specific guidance or offers of credit monitoring. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets; such a check is a practical first step while official details remain sparse. Continue to watch for any formal statement from Modern Eyez or regulators that clarifies what was taken and who is affected.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Village Church of Barrington Listed by nokoyawa Ransomware GroupFresca Listed by nokoyawa Ransomware GroupGuardian Fine Art Services Listed by nokoyawa Ransomware GroupStudio Domaine LLC Listed by nokoyawa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Modern Eyez Listed by nokoyawa Ransomware Group →
Publicly posted by nokoyawa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.