Did Eyemart Express, LLC have a data breach?
Answer
Yes. Eyemart Express, LLC reported a data breach to the Oregon Attorney General on May 12, 2026.
View the official filingWhat the filing says
- Reported to
- Oregon Attorney General
- Filing date
- May 12, 2026
- Breach date
- February 13, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Mailing Address
- Email Address
- Vision Insurance Policy Number
- Prescription and Treatment Information
- Payment Card Information
In plain terms
Eyemart Express, LLC operates as a prominent nationwide optical retailer, providing prescription eyeglasses, sunglasses, and comprehensive eye care services to millions of consumers through its extensive network of retail stores. Because the company routinely collects and processes extensive consumer transactions, schedules comprehensive eye exams, and partners with various vision insurance providers, it maintains vast repositories of sensitive personally identifiable information. This data includes not only standard retail profiles and payment methods, but also detailed health-related records, vision prescriptions, dates of birth, and government-issued identification numbers necessary for medical billing and insurance verification.
In 2026, Eyemart Express reported a major security incident to the Oregon Attorney General, alerting consumers and regulatory bodies that an unauthorized actor gained access to its digital network environment. While retail and healthcare-adjacent organizations are increasingly targeted by sophisticated cybercriminal syndicates, incidents of this magnitude typically involve the exploitation of system vulnerabilities, unauthorized access to underlying customer databases, or the compromise of third-party vendor platforms. Such intrusions often bypass perimeter defenses, allowing malicious actors to dwell undetected within corporate networks and exfiltrate confidential files containing sensitive consumer records before detection occurs.
The exposure resulting from the Eyemart Express data breach threatens victims with severe and multifaceted harms. The compromised dataset likely encompasses sensitive information such as full names, dates of birth, Social Security numbers, vision insurance policy details, and prescription history. When optical and healthcare-related data is exposed alongside financial credentials or identification numbers, victims face an elevated risk of targeted identity theft, medical fraud, unauthorized credit applications, and fraudulent tax filings. Because vision prescriptions and medical records cannot simply be changed like a password, affected individuals are left with a permanent vulnerability to sophisticated social engineering attacks and ongoing financial exploitation.
As a commercial enterprise handling sensitive consumer and medical data, Eyemart Express was legally obligated to implement robust administrative, technical, and physical safeguards to protect its digital infrastructure. Under state data protection statutes, the Federal Trade Commission Act, and applicable privacy regulations, companies holding this caliber of information must maintain rigorous encryption standards, conduct regular security audits, and promptly patch recognized vulnerabilities. The occurrence of a data breach of this scale strongly indicates a failure to maintain reasonable security measures, potentially breaching statutory duties of care owed to their customers and leaving the company legally accountable for resulting damages.
Receiving a formal data breach notification letter from Eyemart Express serves as a legal acknowledgment that your confidential information was compromised due to inadequate corporate security. Under modern class action jurisprudence, the receipt of such a letter provides affected consumers with the legal standing necessary to participate in litigation and pursue accountability, even before financial loss materializes. Our law firm is actively investigating potential class action claims on behalf of individuals whose privacy was violated by Eyemart Express. We evaluate these cases on a strict contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Other filings by Eyemart Express, LLC
Companies often file the same breach in several states. Each filing is listed separately.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Oregon
- Poppins Payroll CompanyYes — reportedOregon · September 30, 2026
- Midvale Indemnity CompanyYes — reportedOregon · September 30, 2026
- Lamb Weston Holdings, Inc.Yes — reportedOregon · September 29, 2026
- Upbound Group, Inc.Yes — reportedOregon · September 28, 2026
- OneMain FinancialYes — reportedOregon · September 28, 2026
- MedImpact Healthcare Systems, Inc.Yes — reportedOregon · September 26, 2026
- Call-On-Doc, Inc.Yes — reportedOregon · September 24, 2026
- Ridgeway Pharmacy LtdYes — reportedOregon · September 21, 2026
- IDScan.netYes — reportedOregon · September 18, 2026
- Kaniksu Community HealthYes — reportedOregon · September 15, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Eyemart Express, LLC.