[SAFEPAY] – Ransomware Victim: bloomfamilyeyesurgeons[.]com

image

Ransomware Group: SAFEPAY

VICTIM NAME: bloomfamilyeyesurgeons[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the SAFEPAY Onion Dark Web Tor Blog page.


AI Generated Summary of the Ransomware Leak Page

The ransomware leak page pertains to Bloom Family Eye Surgeons, a healthcare provider specializing in ophthalmology services based in Newport News, Virginia, United States. The leak was discovered on May 6, 2025, and the attack occurred on the same day, indicating a recent compromise. The company offers various eye care treatments, including surgeries, glaucoma management, and emergency services, with a dedicated team of eye specialists. The leak indicates that sensitive operational data has been accessed, and the page includes a screenshot of internal documents suggesting data exfiltration. No specific personal data of patients or staff is publicly disclosed, but the breach raises concern over the security of the healthcare provider’s digital infrastructure.

The leak page notes the presence of compromised data that may include internal files or information related to the company’s operations. It also mentions a link to a claim URL hosted on the Tor network, suggesting the threat actors are offering the stolen data for sale or exposure. The image thumbnail available on the page shows a screenshot of what appears to be internal documents or system interfaces, indicating the extent of the breach. The incident is associated with the group named “safepay,” though details about the specific data extracted have not been fully disclosed. Overall, the breach highlights the importance of cybersecurity measures within healthcare organizations to protect sensitive operational and potentially confidential patient information.


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.