Prairie Eye and LASIK Center, a full-service eye and vision care provider based in Springfield, Illinois, experienced a data breach involving a ransomware attack. On Aug. 7, 2025, cybercriminal group known as Abyss claimed responsibility for the attack, stating on their Tor-based leak site on the dark web that they had obtained sensitive data belonging to Prairie Eye and LASIK Center.
The exact number of affected patients has not been released, but is believed to be in the thousands. Exposed information may include names, addresses, dates of birth, Social Security numbers, medical records, treatment details, insurance information and payment information.
The severity of the breach is heightened by the fact that both personally identifiable information (PII) and protected health information (PHI) may have been compromised. Personal information in combination with healthcare data is highly sensitive and valuable on the black market.
Prairie Eye and LASIK Center will work to identify and notify affected individuals with the data breach details.
If you believe your personal and protected health information may have been compromised in this breach:
For more information about the healthcare organization, visit the official Prairie Eye and LASIK Center website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.