Eyemart Express Sued Over Customer Data Breach

0
3

Key Takeaways

  • Eyemart Express suffered a February 2024 cyberattack that exposed names, Social Security numbers, medical data, vision insurance details, and other personal information of thousands of customers.
  • The breach was reported to the Texas Attorney General’s Office in April, but affected consumers allege the company delayed individual notice, worsening the risk of identity theft.
  • At least six class‑action lawsuits have been filed, with plaintiffs seeking unspecified damages and a jury trial; the cases are expected to be consolidated.
  • Eyemart Express stated it contained the intrusion on the day it was discovered and is offering free credit monitoring to those whose Social Security numbers were compromised, while mailing notification letters where addresses could be ascertained.
  • The ransomware group PayoutsKing—which may be linked to the notorious BlackBasta syndicate—has claimed responsibility, noting its stealth‑focused tactics such as splitting large database files into smaller blocks to evade detection.
  • The Texas Attorney General’s office estimates more than 45,000 Texans were affected; the national impact is likely several times higher given Eyemart Express’s 250+ stores across 40 states.

Overview of the Data Breach
Eyemart Express, a national optical retailer headquartered in North Texas, disclosed that on February 13, 2024 it learned of unauthorized access to its systems that had begun the previous day. The intrusion compromised a variety of personal data depending on the customer: some had their names, vision‑insurance information, dates of birth, and prescription details exposed; others saw their names, mailing addresses, Social Security numbers, and health‑plan information taken. The company said it was able to contain the incident and secure its networks on the same day it was discovered, but it did not reveal the specific attack vector, the malware used, or the identity of the threat actors in its initial public statement. The breach was first reported to the Texas Attorney General’s Office in April 2024, triggering scrutiny over the timing and adequacy of consumer notifications.

Legal Actions and Class‑Action Lawsuits
In May 2024, Rebecca Montgomery, a Denton‑based Eyemart Express customer, filed a putative class‑action lawsuit alleging that the retailer’s “negligent failure to secure and protect” private information allowed cybercriminals to obtain everything needed for identity theft. The complaint warned that affected individuals would face lifelong risks of fraud and financial harm. William Federman, lead counsel for the plaintiffs, told The News that the litigation aims to protect class members and remediate Eyemart Express’s data‑security shortcomings. Since the Montgomery filing, at least five additional similar suits have been lodged by other customers. Federman indicated that the plaintiffs intend to move for consolidation of the cases, and a federal judge has already granted Eyemart Express extra time to respond to the claims while the consolidation motion is pending.

Company Response and Notification Efforts
Following the discovery of the breach, Eyemart Express issued a news release confirming the cyberattack and stating that it had contained the incident on the day it was detected. The retailer explained that the impact varied across customers, prompting a tiered response: for those whose Social Security numbers were compromised, the company is providing free credit‑monitoring services. Eyemart Express also said it mailed notification letters to all impacted individuals “except when it could not determine an address for them,” though it did not specify the mailing date or the total number of letters sent. The company declined to comment on the pending litigation, citing its policy of not discussing ongoing legal matters. Critics argue that the delay between the April report to the state attorney general and direct consumer notice heightened the potential for misuse of the stolen data.

Ransomware Attribution and Technical Details
While Eyemart Express did not disclose how the breach occurred or who was responsible, the ransomware group PayoutsKing has claimed responsibility for the attack. PayoutsKing emerged in the summer of 2023 and has since been linked to dozens of corporate victims across manufacturing, finance, and other sectors in the United States, Europe, and elsewhere, according to a profile by cybersecurity firm Red Piranha. Security analyst Vincent van Dijk of The Netherlands described the group’s malware as unusually stealthy, noting that its technical execution involves splitting large database files into smaller blocks. This technique enables the malicious code to move more quickly through a network and remain undetected by traditional security tools, distinguishing it from older, more “noisy” ransomware strains.

Impact on Consumers and Outlook
The Texas Attorney General’s office estimates that more than 45,000 Texans were affected by the Eyemart Express breach; given the retailer’s presence in over 250 stores spanning 40 states, the national toll is likely several times higher. Exposed data such as Social Security numbers, medical histories, and vision‑insurance details can be exploited for identity theft, insurance fraud, and other financial crimes, creating long‑term burdens for victims. The ongoing class‑action litigation seeks monetary relief and judicial acknowledgement of the retailer’s alleged negligence, with a potential jury trial on the horizon. As the case proceeds, the outcome may influence how optical and retail companies approach cybersecurity safeguards, breach‑timeliness notices, and consumer‑protection obligations in an era of increasingly sophisticated ransomware threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here