Eyemart Express, LLC Data Breach Notice (Oregon Attorney General)
If you received a notice from Eyemart Express, LLC, here’s what the filing says was exposed, and what to do about it.
Eyemart Express, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on May 12, 2026. The filing puts the incident itself on February 13, 2026.
The February 13, 2026 breach at Eyemart Express exposed personal information belonging to 250 people. The company filed its official notice with the Oregon Department of Justice on May 12, 2026 — 88 days later.
No passwords or credentials were exposed
This is important. The filing lists only personal information and contains no mention of passwords, login details, or any credential material. That means the core account security for anyone who shops at Eyemart Express remains intact. You do not need to change any password connected to this incident.
What the exposed personal information actually enables
Names combined with addresses and other personal details can still be used for targeted identity theft attempts, fraudulent tax filings, or impersonation schemes. While no permanent government identifiers such as Social Security numbers were exposed, the information that was taken retains long-term value to fraudsters because it helps them build convincing profiles or answer security questions on other accounts.
The record does not state that medical details were exposed. Only the broad category of personal information appears in the filing. Your own notification letter is the only document that can confirm exactly which details applied to you.
The 88-day gap between incident and notification
The breach occurred on February 13 and the filing reached Oregon authorities on May 12. That three-month interval is the most concrete fact in the public record. Notification timelines vary by state law and by when an internal investigation concludes, so the gap alone does not prove any specific failure. It does, however, give you a clear timeline of when the company knew it had to notify affected customers.
How to tell whether this breach involves you
Eyemart Express is required to notify affected individuals directly, almost always by mail to the last known address. If you have not received a letter, it is likely your records were not part of the 250 affected. However, if you have moved since February 13, 2026, a letter may have gone to an old address. In that case, contact Eyemart Express customer service directly to confirm whether your information was included.
What remains under your control
Because no passwords were exposed and no reissuable government identifiers appear in the record, the breach does not create open-ended account takeover risk at Eyemart itself. The realistic ongoing risk is that pieces of your personal profile are now available to help fraudsters succeed on other sites or services where you already have accounts.
That risk cannot be eliminated, but it can be reduced through deliberate monitoring rather than panic. The information taken cannot be “taken back,” yet its usefulness to criminals drops sharply once they realize the targeted person is watching for fraud.
Concrete steps that address this specific exposure
- Place a fraud alert with one of the three major credit bureaus. A fraud alert forces lenders to verify your identity before opening new accounts in your name. It is free, lasts one year, and automatically notifies the other two bureaus.
- Review your Explanation of Benefits statements from any health insurer. Even though medical details are not confirmed in the filing, cross-checking recent claims can reveal whether someone attempted to use your identity for medical services.
- Monitor existing financial accounts weekly for the next three months. Look for small test charges or unfamiliar addresses on credit cards, bank accounts, and retail accounts where you used your Eyemart Express information.
- Freeze your credit reports if you do not expect to apply for new credit soon. A credit freeze stops new accounts from being opened without your explicit permission and is more protective than a fraud alert.
- File your taxes early next year and respond immediately to any IRS notice. Identity thieves sometimes use stolen personal details to file fraudulent returns; early filing reduces the window they can exploit.
The letter you may have received from Eyemart Express remains the single best indicator of whether you were in the affected group. Absence of that letter, combined with no change of address since mid-February 2026, is strong evidence that your information was not exposed in this incident.
Report details & sourcing
Related breaches
ReliaQuest, LLC Listed by Shinyhunters Ransomware Group
This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. D…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…