Eyemart Express, LLC Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what’s now in circulation.
Eyemart Express, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 24, 2026, and the notice lists name, social security number, driver's license or washington id card number, financial & banking information, full date of birth, passport number, health insurance policy or id number and medical information among the information exposed. The filing puts the incident itself on February 12, 2026.
The February 12, 2026 breach at Eyemart Express means that for 1,704 Washington residents, a single incident has placed highly sensitive personal documents into unknown hands. Because the company waited 162 days—until July 24, 2026—to file the notice, you have had months of unknown exposure before learning about it.
Your Social Security Number and Date of Birth Are Now a Permanent Identity-Theft Tool
If you were among those notified, attackers or whoever ultimately receives the data now hold the exact combination—your name, Social Security number, and full date of birth—that credit bureaus, banks, and government agencies use to verify identity. This pairing cannot be replaced. Unlike a credit card or password, you cannot cancel it or have it reissued.
The filing also lists driver’s license or Washington ID card numbers, passport numbers, financial and banking information, health insurance policy or ID numbers, and medical information. These categories together create a complete profile that can be used for everything from opening new accounts in your name to filing fraudulent tax returns or medical claims.
What the 162-Day Gap Actually Means for You
The incident occurred on February 12, 2026. The Washington Attorney General received the filing on July 24, 2026. That five-and-a-half-month interval is the single most concrete fact in the record. During those months the data could have been copied, sold, or used without your knowledge. The filing does not disclose when the breach was discovered or how long the information was accessible, so the safest assumption is that the material has been at large for some time.
No passwords were exposed. The record lists no credential-related fields. This is genuinely good news: your Eyemart Express account itself is not at immediate risk of takeover. The danger lies entirely in the biographic and financial data that cannot be changed.
Why Medical Information and Health Insurance Details Matter Here
Medical information combined with a health insurance policy number gives fraudsters the ability to file false claims, order prescriptions, or obtain care in your name. These records often contain diagnosis codes or treatment details that can later be used for blackmail or to manipulate future insurance decisions. Once released, this data cannot be recalled.
A passport number paired with a Social Security number and date of birth is especially valuable on the dark web because it can support applications for new government-issued documents or international accounts. The same combination is frequently used to create synthetic identities that persist for years.
The Records Belong to Patients, Not Customers
Eyemart Express is an optical retailer. The 1,704 people affected are patients whose vision-care records included far more than prescription details. The filing makes clear that the exposed data reaches well beyond routine retail transactions into core identity and health documents. Anyone who visited an Eyemart location and provided this information between the company’s data-collection practices and the February 2026 incident may have been included.
How to Determine Whether You Were Affected
Eyemart Express is required to notify affected Washington residents directly, usually by mail. If you have not received a letter, it is likely your records were not part of this incident. However, if you have moved since February 12, 2026, or if your address on file is outdated, the letter may never have reached you. In that case, contact Eyemart Express directly using the customer-service number on their official website to confirm whether your information was included.
What You Can Still Control
While you cannot change your Social Security number, date of birth, or passport number, you retain significant power over how that information is used going forward.
Place a freeze on your credit files at Equifax, Experian, and TransUnion immediately. This prevents new accounts from being opened in your name even if someone presents your exact details. The freeze is free, reversible when you need to apply for credit, and remains one of the most effective defenses against SSNs that are already circulating.
Monitor your Explanation of Benefits statements from every health insurer you hold. Look for claims you did not file or services you did not receive. Fraudulent medical billing is often the first visible sign that your health insurance ID has been misused.
Review bank and credit-card statements for small test charges that often precede larger fraud. Set up transaction alerts so you are notified in real time rather than waiting for a monthly statement.
Consider requesting an Identity Theft Report from the FTC if you later see suspicious activity. Having that report on file speeds up disputes with creditors and removes much of the bureaucratic burden that victims otherwise face.
The Long-Term Reality of This Exposure
A Social Security number and date of birth do not lose their value after a few months. Criminal networks continue using stolen identities for years—sometimes a decade or more—because the identifiers remain valid. The addition of your driver’s license, passport, and medical data simply increases the number of plausible scenarios an attacker can construct.
This is why the 162-day notification delay matters. Every additional week the data moved undetected increased the chance it reached professional fraud operations rather than an opportunistic thief. The filing itself offers no information about encryption, access controls, or the root cause, so those uncertainties remain.
What is certain is that 1,704 patients now share the same permanent risk profile. The categories listed—particularly the SSN, full date of birth, passport number, and medical information—cannot be retired or replaced the way a compromised credit card can. Your defense therefore shifts from prevention of exposure to relentless detection and rapid response whenever that data surfaces in new accounts or claims.
Stay vigilant. The letter from Eyemart Express is the beginning of your awareness, not the end of the risk. The combination now outside your control will remain valuable to someone else for the rest of your life. The steps you take in the coming days determine how much of that risk you can still contain.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Eyemart Express, LLC.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…