OPMT Targeted: The BianLian Ransomware Attack"

Incident Date:

April 22, 2024

World map



OPMT Targeted: The BianLian Ransomware Attack"


Optometric Physicians of Middle Tennessee




Nashville, USA

Tennessee, USA

First Reported

April 22, 2024

Ransomware Attack on Optometric Physicians of Middle Tennessee by BianLian Group

Attack Overview

Optometric Physicians of Middle Tennessee (OPMT), a prominent eye care provider in the Middle Tennessee region, recently fell victim to a ransomware attack orchestrated by the notorious BianLian group. The attack resulted in the exfiltration of approximately 1.5 TB of sensitive data, including finance data, HR records, patient personally identifiable information (PII), protected health information (PHI), biometric data, contracts, and SQL databases.

Company Profile

OPMT is a key player in the eye care industry within Tennessee, offering a wide array of services such as eye exams, contact lens fittings, and treatments for various eye conditions. The company is known for its commitment to cutting-edge technology and high-quality personalized care. Led by Dr. Richard D. Durocher, OPMT operates multiple locations across the state and serves a substantial patient base.

The organization's emphasis on advanced diagnostic technology and participation in clinical research studies sets it apart in the healthcare sector. However, this focus on technology and the storage of extensive sensitive data may also increase its attractiveness as a target for cybercriminals like the BianLian group.

Implications of the Attack

The breach poses significant risks to the privacy and security of OPMT's stakeholders, including potential financial and reputational damage. The exfiltration of such a vast amount of sensitive data could lead to severe consequences, impacting patient trust and compliance with healthcare privacy regulations.

Ransomware Group Profile

BianLian has evolved from a banking trojan to a sophisticated ransomware operation, known for its global attacks on various sectors, particularly healthcare. The group employs advanced tactics including the use of compromised RDP credentials, custom backdoors, and extensive data exfiltration techniques. Their recent shift to primarily exfiltration-based extortion highlights a strategic pivot that maximizes potential impact on the victim organizations.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.