The Gentlemen ransomware crew has added an ophthalmology group to its leak site, the latest in a year of healthcare listings from the same operation.
Ransomware.live logged the post on September 15, estimating that the attack on Hattiesburg Eye Clinic, a Mississippi-based practice and surgical center, occurred a day earlier. HookPhish reported the same claim. No victim count, data categories, or exfiltration volume have surfaced, and the clinic has not confirmed an incident.
Treat a listing as a claim, not proof. Extortion crews recycle old data and sometimes name organizations they never breached. Eye clinics remain a target worth watching, though: they run surgical scheduling, imaging, and insurance systems that cannot tolerate downtime, and most do not staff a dedicated security team.
Law firms tied to ClassAction.org have opened an investigation and want current and former patients and staff to make contact. For other practices in the region, the practical response matches any leak-site post: review identity provider logs, sweep remote access and VPN sessions, rotate credentials, and verify backups restore.