Dallas

Farmers Branch Eyeglass Chain Eyemart Express Rocked by Customer Data Breach

AI Assisted Icon
Published on July 25, 2026
Farmers Branch Eyeglass Chain Eyemart Express Rocked by Customer Data BreachSource: Google Street View

Customers of Farmers Branch-based Eyemart Express are getting more than new frames this year. Yesterday, the national eyewear chain confirmed that a February cybersecurity incident may have exposed customers' personal and medical information, triggering federal reporting requirements and at least one class-action lawsuit.

What Eyemart Reported

Eyemart says it learned on Feb. 13 that its systems had been accessed without authorization on Feb. 12, and that it contained the intrusion and secured systems the same day. The retailer said it mailed letters to affected customers and is offering credit monitoring to people whose Social Security numbers were involved. Eyemart also directed customers to watch for suspicious activity and to call its helpline at (800) 655-4635 to confirm whether they were affected, according to CBS News texas.

What Was Exposed

The company’s notices and legal summaries indicate the data involved varies by person but may include names, addresses, dates of birth, Social Security numbers, driver’s-license numbers, health-plan and vision-insurance details, and eyeglass prescriptions or purchase records. That mix of personally identifiable information and protected health information is what makes the incident particularly sensitive for victims. A report filed with state authorities and summarized by consumer legal outlets lists Social Security numbers and medical information among the likely categories, according to ClassAction.org.

Scope and Scale

Per the HHS Office for Civil Rights breach portal, the company submitted a May 18 report that listed about 25,000 individuals affected in a hacking/IT incident. California’s Attorney General breach list also shows a Feb. 13 date tied to Eyemart’s notification to regulators, per the California Attorney General. Eyemart operates more than 250 stores in 42 states and is headquartered in Farmers Branch, Texas, which means customers nationwide could be affected, per CBS News Texas.

Legal Fallout

At least one class-action complaint, Lewis v. Eyemart Express, was filed April 30 in U.S. District Court for the Northern District of Texas alleging the company failed to safeguard customer and patient data; the case appears on public court dockets. Security monitors and law-firm summaries say a threat actor known as Payouts King later claimed on the dark web to have exfiltrated a large trove of Eyemart files, a posting noted by legal investigators and counsel. Those filings and claims have prompted outreach from attorneys and consumer-protection groups as the litigation and regulatory reviews proceed, according to court and legal summaries available online.

What to Do if You Were Affected

If you received a breach notice, experts recommend monitoring bank and credit statements and checking credit reports for unfamiliar accounts or inquiries. Consider placing a fraud alert or credit freeze if you see suspicious activity, retain your breach notice for records, and enroll in any complimentary credit monitoring the company provides. The Federal Trade Commission’s IdentityTheft.gov offers step-by-step guidance and sample letters for people who suspect identity theft.

Company Response and Next Steps

In notices to regulators, Eyemart said it contained the incident, began notifying affected people, and is reviewing internal training, processes, and procedures as part of its investigation, according to legal summaries of the company’s filings. Regulators and federal law-enforcement partners may follow up because the incident involved personal and medical information that can carry heightened legal obligations. Customers with questions should check any letter they received or contact the helpline listed in that notification while keeping an eye on official updates from regulators and the company.