I’ve been following this story for a few weeks now, and one number keeps sticking with me: five months. Someone got into Eyemart Express’s systems on February 12. The company caught it and shut it down the very next day, which is honestly a fast catch by any measure. Customers got their letters in late July. Five months between “we found it” and “you found out.” That gap is what I want to walk through here, because it’s the part every business owner should sit with, not just the breach itself.

Here’s what’s actually known: the timeline, what was taken, who’s claiming the attack, and what still hasn’t been said.

What happened, and when

Eyemart Express is a Texas company, headquartered in Farmers Branch, with more than 250 stores in 42 states. I pieced this timeline together from the company’s own notice, state filings, and breach-tracking sites:

  • February 12, 2026: someone gets into Eyemart’s systems.
  • February 13: the company finds the intrusion and shuts it down.
  • March 10: an extortion group calling itself Payouts King lists Eyemart on its dark web leak site, claiming to have taken about 435 gigabytes of internal data and threatening to publish it.
  • April 17: Eyemart reports the breach to the Texas Attorney General. Breach trackers citing that filing put the number of affected Texans above 45,000. A nationwide total hasn’t been published.
  • Late July: notification letters start reaching customers.

The letters are what made the news. Everything before them had been sitting in public view on breach-tracking sites for months.

This one’s local, too. Eyemart has a store on the I-35 frontage road in San Marcos, in the Guadalupe Crossing shopping center, and two more in Austin. Some of these letters are landing in Hays County mailboxes right now.

What was compromised

It varied person to person. For some customers it was names, vision insurance details, birth dates, and eyeglass purchases or prescriptions. For others it included addresses, Social Security numbers, driver’s license or government ID numbers, and health plan information.

The attackers’ own claim goes further, corporate correspondence, payroll reports, employee files, contracts. I’d take that part with a grain of salt; extortion groups exaggerate to raise the pressure. But the company’s own letters confirm the categories that matter most to customers: identity data sitting right next to health-adjacent records.

Eyemart is offering free credit monitoring to anyone whose Social Security number was involved. Its line for questions is 800-655-4635.

Who was behind it

Payouts King, the group that claimed the attack, is an extortion crew. If you haven’t heard of them, that’s normal, these groups appear, rebrand, and disappear constantly. What they all share is the same business model: break in, copy data, demand payment, and threaten to publish on a leak site if the victim doesn’t pay. Some also encrypt systems on the way out, which is exactly why a tested backup and recovery plan matters just as much as keeping intruders out in the first place. Eyemart says it contained the intrusion within a day, which tells me the leverage here was the stolen data, not locked-up computers.

Eyemart hasn’t publicly confirmed the group and hasn’t said whether any ransom discussion happened. It has said it’s cooperating with federal law enforcement. Don’t expect a tidy ending here. Attribution in these cases stays murky, and the people running leak sites are usually overseas and out of reach.

How the attackers got in

Eyemart hasn’t said, and honestly, it may never say. Companies almost never volunteer technical details outside a courtroom, and notification letters aren’t required to include them.

What I can tell you is how this class of attack usually starts: stolen or phished employee credentials, remote access like a VPN without multi-factor authentication, or an unpatched system facing the internet. None of that is confirmed for Eyemart specifically. At least one proposed class action lawsuit has already been filed, and if it moves forward, the how tends to come out in discovery.

About that five-month gap

Texas law says a business that discovers a breach has to notify affected people without unreasonable delay, and no later than 60 days after determining the breach occurred. If more than 250 Texans are affected, the Texas Attorney General has to be notified within 30 days. HIPAA-covered entities have their own 60-day clock for health information.

So how does five months happen? Sometimes legally. Law enforcement can ask a company to hold off while an investigation runs, and figuring out exactly whose data was taken can take forensic teams months, which affects when the clock actually starts. Eyemart filed with the state in April and letters went out in late July; whether that timing fits the 60-day rule depends on facts that aren’t public, and it’s exactly the kind of question the pending lawsuits will dig into. I’m not saying they broke any rules here. I genuinely don’t know.

Here’s what I do know. Your customers don’t read breach statutes. They remember one thing: how long you knew before they did. For five months, Eyemart customers had Social Security numbers and insurance details sitting in someone else’s hands with no idea they should be watching their credit. Whatever the legal explanation turns out to be, that’s the part people won’t forget.

If you keep health or insurance data, this is closer to home than you think

An eyeglass retailer doesn’t sound like a healthcare company. But look at what was actually in those files: vision insurance details, health plan information, prescriptions. Pair any of that with a name, birth date, and Social Security number, and you’ve handed a fraudster everything they need.

I see plenty of Central Texas businesses holding the same kind of data. Optometrists and dental offices, obviously. Also chiropractors, therapy practices, benefits brokers, and any office that handles employee insurance enrollment. If that’s you, breach notification law isn’t some abstract thing that happens to other companies. It comes with a clock, and that clock starts whether you’re ready for it or not.

What being ready actually looks like

The reason breach notifications drag on for months is usually not a cover-up. It’s that nobody can tell what was actually taken. If your systems don’t log who accessed what, your forensic team can’t reconstruct it, and you end up sending letters to everyone, months late, about everything.

Being ready comes down to a few specific, unglamorous things. Logging and monitoring that can actually answer “what did they touch?” A written incident response plan with real names and phone numbers on it, not a binder nobody’s ever opened. Knowing your notification deadlines before you need them, not while you’re in the middle of an incident trying to Google them. And if your business has fewer than 250 employees, Texas SB 2610 gives you a real reason to formalize all of it: adopt a recognized cybersecurity framework and you get safe harbor from punitive damages if a breach ever lands you in court.

None of this stops every attack. Eyemart caught theirs in a day, and it still took five months to send letters. Detection speed and notification speed are two completely different problems, and the second one is where trust actually lives.

I run safemode IT, a managed IT and cybersecurity company here in Kyle, and this kind of readiness work is what I do for Central Texas businesses every day. If you’d rather talk it through than read about it, call me at 512-761-7652, or book a free IT assessment.

Stay safe and secure!

FAQ

Who was responsible for the Eyemart Express data breach?

An extortion group calling itself Payouts King claimed responsibility on its dark web leak site in March 2026, saying it took about 435 GB of internal data. Eyemart hasn’t publicly confirmed the attacker and says it’s cooperating with federal law enforcement.

How did the Eyemart Express breach happen?

Eyemart hasn’t disclosed the technical details, and it might never. The intrusion happened February 12, 2026, and was discovered and contained the next day. Attacks like this usually start with stolen credentials, phishing, or an unpatched internet-facing system, but there’s no public confirmation of the method here.

How many people were affected?

Eyemart hasn’t published a total. Breach trackers citing the company’s April 2026 filing with the Texas Attorney General report more than 45,000 Texas residents affected. The nationwide number isn’t public.

Are there Eyemart Express locations in Central Texas?

Yes. There’s a store at 200 N Interstate 35 in San Marcos, in the Guadalupe Crossing shopping center, plus two Austin locations on Airport Boulevard and South I-35. The breach involved company systems rather than a single store, so whether you’re affected depends on your customer records, not which location you visited. Call Eyemart at 800-655-4635 to check.

I got a letter from Eyemart Express. What should I do?

Take the free credit monitoring, it costs you nothing. Consider freezing your credit with all three bureaus, also free. Watch your explanation of benefits statements from your health and vision insurers for claims you don’t recognize. Questions about whether your data was involved go to Eyemart at 800-655-4635.

How fast does a Texas business have to report a breach?

Under Texas Business and Commerce Code 521.053, affected individuals must be notified without unreasonable delay and no later than 60 days after the business determines a breach occurred. If 250 or more Texas residents are affected, the Texas Attorney General must be notified within 30 days. HIPAA-covered entities also have a 60-day deadline for breaches of health information.

What is the Texas SB 2610 safe harbor?

A Texas law effective September 1, 2025. Businesses with fewer than 250 employees that implement a recognized cybersecurity framework are protected from punitive damages in lawsuits following a data breach. It doesn’t prevent lawsuits, but it caps the worst of the exposure, and it rewards businesses that prepared.

Not sure where your IT actually stands? Score your business in about 3 minutes on security, backup, support, and Texas compliance. Free, anonymous, no signup.

Take the free assessment