Eyemart Express Data Breach: What Customers Should Do After the Cyberattack

Stolen prescription details can fuel convincing scams even when no fraudulent credit account appears.

Eyemart Express customers should verify whether their information was affected, enroll in any legitimate protection service offered in their notice, freeze their credit if a Social Security number was exposed, and monitor financial, insurance, and medical records for unfamiliar activity. For example, a customer whose notice lists both a Social Security number and vision-insurance information should check credit reports for new accounts while also reviewing insurance explanations of benefits for eye exams, frames, lenses, or other services they never received. The response should match the information listed in each customer’s letter because the exposed data reportedly varies by person. Names, addresses, birth dates, Social Security numbers, health-plan information, vision-insurance details, and eyeglass purchase or prescription records may have been involved.

Customers should also expect convincing phishing attempts that refer to their eyewear, insurer, prescription, or local store; familiarity with those details does not prove that a message is authentic. Eyemart Express said it learned of unauthorized access on February 13, 2026, involving activity from the previous day. The company reported containing the incident and securing its systems that same day. It later mailed notices to affected people when an address was available and offered free credit monitoring to those whose Social Security numbers were involved, according to [CBS Texas](https://www.cbsnews.com/texas/news/eyemart-express-data-breach-2026/).

Table of Contents

What Happened in the Eyemart Express Data Breach?

Eyemart Express reported that its systems were accessed without authorization on February 12, 2026. The company discovered the incident on February 13, contained it, launched an investigation, and began reviewing the affected records. A notification filed with the [California Attorney General](https://oag.ca.gov/ecrime/databreach/reports/sb24-626998) identifies February 13 as the breach date, while the accompanying notice says the unauthorized access occurred the day before. Containment and notification are separate stages of a breach response. Stopping access can take hours, but determining which files were viewed or copied may require weeks of forensic work and document review.

In one notice template filed with California, Eyemart said it could not identify the affected files with reasonable certainty until around March 17. That helps explain why a customer may receive a letter months after the underlying intrusion. The available notices do not establish that every Eyemart Express customer had every listed data element exposed. A person whose record contained only contact and eyewear information faces a different risk from someone whose Social Security number, date of birth, and insurance information were involved. Customers should rely on the personalized “What Information Was Involved” section of their own notice rather than a general list circulating online.

Personal, Insurance, and Prescription Data May Create Different Risks

A stolen Social security number and birth date can support new-account fraud, fraudulent loan applications, tax-related identity theft, and attempts to pass identity-verification checks. Names and addresses may seem less sensitive by comparison, but they can make an impersonation attempt more credible. A scammer who knows a customer’s full name, former address, and eyewear provider may sound more convincing than someone making a generic robocall. Health-plan, vision-insurance, prescription, and purchase information introduce risks that ordinary credit monitoring may not detect.

Someone could potentially use insurance details to seek benefits, alter contact information, or build a targeted scam around a real provider relationship. For example, a fraudulent message might claim that a recent lens order requires an additional payment and include the correct store location or type of purchase. Prescription records may also reveal sensitive health information even when they cannot be used directly to open a bank account. Customers should not assume that freezing their credit solves this part of the problem. Credit bureaus generally monitor borrowing activity, not disputed insurance claims, altered patient records, or phishing messages based on healthcare details.

Watch for Breach-Themed Phishing and Medical Identity Fraud

Data-breach notifications often create a second opportunity for criminals. A recipient may receive an email or text claiming that enrollment in credit monitoring is about to expire, that compensation is available, or that identity verification requires a Social Security number. The message may copy Eyemart Express branding or mention the cyberattack reported in the news. Do not use a phone number, QR code, or enrollment link from an unexpected follow-up message without verifying it against the original mailed notice.

Eyemart Express told customers they could call 800-655-4635 to determine whether they were affected, according to CBS Texas. A legitimate enrollment process may require the unique code printed in the notice, but it should not require payment for a service the company says it is providing free. Medical identity misuse can be quieter than credit fraud. Review explanations of benefits and online insurance claims for providers, dates, or services you do not recognize. For example, an unfamiliar claim for an eye examination in another city should be disputed with the insurer even if the claim generated no bill, because inaccurate information could affect benefit limits or become part of an insurance record.

Actions Eyemart Express Customers Can Take Now

Start by keeping the breach letter and recording exactly which information it says was involved. Confirm the notice through a trusted source, then enroll in the offered monitoring before the deadline printed in the letter. Type the enrollment address manually or use the contact information in the verified notice rather than relying on a search advertisement, unsolicited email, or social-media post. If a Social Security number was exposed, place a security freeze with Equifax, Experian, and TransUnion. A freeze is free, remains in place until lifted, and generally prevents a lender from accessing the credit file needed to approve a new account.

The tradeoff is inconvenience: a customer applying for an apartment, credit card, auto loan, or another service involving a credit check may need to temporarily lift the freeze. A fraud alert is less restrictive. It instructs lenders to verify the applicant’s identity but does not block access to the credit report. Contacting one credit bureau is sufficient to start an initial alert because that bureau must notify the other two, while a freeze must be placed separately with all three. The [Federal Trade Commission’s comparison](https://consumer.ftc.gov/articles/credit-freezes-and-fraud-alerts) explains that an initial fraud alert lasts one year, whereas a freeze lasts until the consumer removes it.

Credit Monitoring Has Important Limitations

Credit monitoring is useful for detecting changes to a credit file, but it does not prevent every form of identity fraud. Alerts generally arrive after activity has been reported, and they may not cover bank-account takeovers, tax filings, insurance misuse, payday loans that do not reach a major bureau, or fraudulent use of prescription information. Enrolling in monitoring should therefore supplement a credit freeze and account review, not replace them. Customers should examine credit reports for accounts, addresses, employers, and hard inquiries they do not recognize.

Reports can be obtained through [AnnualCreditReport.com](https://www.annualcreditreport.com/), the federally authorized source identified in the breach notice. A credit score by itself is not enough: an unfamiliar inquiry or incorrect address may appear before a fraudulent account produces a noticeable score change. Bank and card alerts can provide another layer of detection, particularly when configured for small transactions and changes to contact details. A warning is necessary, however: replacing a payment card will not address exposure of a Social Security number or medical information. Conversely, a credit freeze will not stop someone who already has access to an existing bank, email, insurance, or retail account.

Passwords, Email Accounts, and Reused Credentials

The reported categories of customer information do not by themselves prove that Eyemart Express account passwords were exposed. Even so, customers should change an Eyemart password if they reused it elsewhere, notice unexpected account activity, or receive a legitimate password-reset warning. Each account should have a unique password, with multifactor authentication enabled where available.

Email security deserves particular attention because an email account can be used to reset passwords for other services. For example, someone who gains access to a customer’s inbox may search for insurance documents, intercept security codes, or hide account-warning messages. Review active email sessions, recovery addresses, forwarding rules, and recently deleted messages if anything appears suspicious.

How to Document and Report Suspected Identity Theft

Keep a dated record of suspicious activity, including screenshots, letters, credit-report entries, insurance statements, case numbers, and the names of representatives contacted. Ask a creditor or insurer to confirm disputed activity in writing. If a fraudulent account appears, contact the company’s fraud department, freeze or close the account, and dispute the entry with each credit bureau reporting it.

Identity-theft victims can file a report at [IdentityTheft.gov](https://www.identitytheft.gov/) and receive an FTC Identity Theft Report and a personalized recovery plan. Some creditors may request that report or a police report before blocking fraudulent debt. A practical case file might contain the Eyemart Express notice, the affected credit-report page, an FTC report, a police-report number, certified-mail receipts, and written confirmation that the fraudulent account was removed.

Frequently Asked Questions

How can I find out whether I was affected by the Eyemart Express cyberattack?

Review any letter sent by Eyemart Express and verify it using independently confirmed contact information. The company reportedly provided 800-655-4635 for people seeking to confirm whether they were affected. Do not provide sensitive information to an incoming caller claiming to represent the company.

What information may have been exposed?

The information varies by person but may include names, addresses, dates of birth, Social Security numbers, health-plan or vision-insurance information, and eyeglass purchase or prescription records. A personalized notice should identify the categories associated with the recipient.

Should I freeze my credit?

A freeze is especially appropriate when a Social Security number was involved. It is free and can make new-account fraud substantially harder, but it must be placed separately with Equifax, Experian, and TransUnion.

Is the free credit monitoring enough?

No. Monitoring may alert a customer after credit-file activity occurs, but it generally does not prevent new accounts or detect medical, insurance, tax, and existing-account fraud. Use it alongside credit freezes, account alerts, and reviews of insurance claims.

What should I do if I find an unfamiliar account or insurance claim?

Contact the creditor, provider, or insurer through an official channel, dispute the activity, preserve written records, and report identity theft at IdentityTheft.gov. Change credentials immediately if an existing online account was accessed.


You Might Also Like