LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Eyemart Express, LLC Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

Eyemart Express, LLC Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 24, 2026
Eyemart Express, LLC Data Breach Notice (Washington Attorney General)

Occurred February 12, 2026 · publicly disclosed July 24, 2026. Approximately 1704 people affected.

CRITICAL
Severity
1704
People affected
8
Data types exposed
July 24, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Eyemart Express, LLC Data Breach Notice (Washington Attorney General) (reported July 24, 2026) exposed Name, Social Security Number, Driver's License or Washington ID Card Number and Financial & Banking Information belonging to roughly 1704 people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1704 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Eyemart Express, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 24, 2026. The notice states that the incident itself occurred on February 12, 2026, and that 1,704 people were affected. Among the information listed as exposed are names, Social Security numbers, driver’s license or Washington ID card numbers, financial and banking information, full dates of birth, passport numbers, health insurance policy or ID numbers, and medical information.

For people whose records were involved, the combination of identity, financial, and health-related data raises practical risks of fraud and misuse. Public detail beyond the filing remains limited; the notice does not describe how the incident occurred or confirm the full geographic scope of those affected.

Breaking down the breach

According to the Washington Attorney General filing, Eyemart Express, LLC reported the matter on July 24, 2026. The filing places the incident on February 12, 2026, and states that 1,704 individuals were affected. The notice lists the categories of information exposed as name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information.

The public record does not describe the technical method of access, whether systems were encrypted or held for ransom, how long unauthorized access lasted, or whether data was exfiltrated in bulk or selectively. No threat actor is named in the disclosure. Timing between the February incident date and the July reporting date is stated in the filing; reasons for the interval are not detailed in the available notice.

How a breach like this happens

Incidents that expose customer or patient-adjacent records at retail and healthcare-adjacent businesses often begin with compromised credentials, phishing that reaches staff email or remote access tools, unpatched software on internet-facing systems, or misuse of legitimate administrative access. Once inside a network, attackers commonly look for databases, document stores, or backup repositories that hold identity and billing data.

In general terms, organizations that schedule appointments, process insurance, or handle payments may retain names, dates of birth, government ID numbers, insurance identifiers, and clinical or billing notes in the same environment. If those systems are reachable without strong segmentation, multi-factor authentication, or timely monitoring, a single foothold can lead to broader collection of records. None of these patterns is confirmed for this specific event; they describe how similar incidents typically unfold when method details are later disclosed elsewhere.

About Eyemart Express, LLC

Eyemart Express, LLC operates in the optical retail sector, providing eyewear and related vision services to consumers. Businesses of this type commonly collect personal identifiers to open accounts, verify insurance eligibility, process payments, and maintain prescription or visit records. They may also hold driver’s license or state ID information for identity verification and financial details for billing or financing.

A breach at such an organization is consequential because the data needed to deliver routine vision care overlaps with data useful for identity theft and insurance fraud. Customers often provide sensitive identifiers once and expect them to remain protected across appointments and claims. When those records are exposed, the impact can extend beyond a single store visit to longer-term credit, tax, and medical-identity risks.

What was likely exposed

The Washington filing names the following categories as exposed: name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information. These are the data types stated in the notice; the filing does not itemize every field within “financial and banking information” or “medical information,” nor does it confirm whether every affected person had every category on file.

Organizations in optical retail and vision services typically hold contact details, dates of birth, insurance member IDs, prescription or exam-related notes, and payment data. Passport numbers and full government ID numbers are less universal but can appear when identity verification or certain financing steps require them. Exact contents for each individual remain as described in the notice; anything beyond the listed categories is unconfirmed in the public disclosure.

Why it matters

Exposure of Social Security numbers, dates of birth, and government ID numbers can enable new-account fraud, tax-refund fraud, and synthetic identity schemes. Financial and banking information can support unauthorized transactions or account takeover attempts. Health insurance identifiers and medical information can be misused for fraudulent claims or to build detailed profiles that make phishing and social-engineering attempts more convincing.

For the organization, a breach of this kind brings notification costs, potential regulatory scrutiny, and the need to support affected individuals with monitoring or other remedies if offered. For affected people, the harm is concrete rather than abstract: monitoring credit, watching insurance explanations of benefits for unfamiliar claims, and treating unsolicited requests for further personal data with heightened caution. The filing does not state whether criminal charges, civil actions, or specific remediation packages have been finalized.

Were you affected?

If you have been a customer of Eyemart Express, LLC and are concerned you may be among the 1,704 people referenced in the Washington notice, consider steps that do not depend on further corporate detail. Review credit reports for unfamiliar accounts, place fraud alerts or credit freezes with the major credit bureaus if appropriate, and watch bank and insurance statements for activity you do not recognize. Be alert to phishing that references an optical visit, insurance claim, or “breach assistance” and that pressures you to share more data or click unknown links.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Official updates, if any, would come from the company or from regulators such as the Washington State Attorney General; treat unsolicited messages claiming to represent either with skepticism until you verify them through known channels.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyEyemart Express, LLC security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Eyemart Express, LLC’s full breach history →
RelatedMore incidents at Eyemart Express, LLC

More recent breaches

Chelan County, WA Data Breach Notice (Washington Attorney General)August 11, 2026Kovack Financial, LLC Data Breach Notice (Washington Attorney General)August 10, 2026American Addiction Centers Data Breach Notice (Washington Attorney General)August 7, 2026Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)August 7, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Eyemart Express, LLC Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram