HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Asheville Eye Associates, PLLC
bd_694b2250a9e049d1 · schema v1 · pii pii-v1
Full breach record for Asheville Eye Associates, PLLC →Asheville Eye Associates, PLLC notified South Carolina residents of a data security incident detected on November 18, 2024. An unauthorized party accessed the network and acquired files containing names, addresses, SSNs, medical treatment info, and health insurance data. The investigation concluded April 14, 2025. Affected individuals were offered 12-24 months of credit monitoring.
Leak gap clock✗ Leak >180d30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 207 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5d1589dd656b977aMontana State AGfiled 2025-06-13Candidate
- bd_61636977e5587feaIndiana State AGfiled 2025-06-13Verified
- bd_66c3cf170bf79f25Vermont State AGfiled 2025-06-13Verified
- bd_fc537b3102571495New Hampshire State AGfiled 2025-06-13Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Consumer%20Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- ee9a260564673580b55b8ca112cc836f3755d68d437677c2c923eede1aae8ceb
Reporting entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
Victim entity
- Name
- Asheville Eye Associates, PLLCnorm: asheville eye associates
- Domain
- ashevilleeye.com
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- —
- Notification sent
- Jan 31, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.