TL;DR: Ransomware group PayoutsKing posted on dark web forums on March 10, 2026, claiming to have exfiltrated 435 GB of internal data from Eyemart Express, a national optical retailer with nearly 250 stores across 42 states. The stolen data reportedly includes Social Security numbers, medical records, health insurance information, driver’s licenses, dates of birth, financial documents, and payroll records. Eyemart Express filed a breach disclosure with the Texas Attorney General on April 17: 38 days after the attackers went public. As of early May, the company still hasn’t notified affected individuals or disclosed how many customers are impacted. Multiple law firms have launched class action investigations. If you’ve ever visited an Eyemart Express, Vision4Less, Visionmart Express, or Eyewear Express location, your data may be compromised.
What Happened
On March 10, 2026, the ransomware group PayoutsKing posted a claim on its dark web leak site: it had breached Eyemart Express and stolen 435 gigabytes of the company’s internal data [1]. The group’s message was blunt: “The full data set will be released if Eyemart Express fails to negotiate. Contact us immediately” [1].
Eyemart Express is not a small operation. Founded in 1990, the company runs nearly 250 retail locations across 42 states under multiple brands: Eyemart Express, Vision4Less, Visionmart Express, and Eyewear Express [2]. They do eye exams. They fill prescriptions. They take your insurance information. And now a ransomware group has all of it.
The company didn’t file a breach disclosure with the Texas Attorney General’s Office until April 17, 2026: 38 days after the attackers publicly announced the breach [3]. That’s not 38 days after the breach happened. That’s 38 days after the attackers told the whole internet about it.
What Was Stolen
Here’s where it gets bad. Optical retailers aren’t just selling you frames. They’re processing medical exams, running insurance claims, and storing some of the most sensitive personal data you have. According to breach reports and the PayoutsKing claim, the stolen data includes [2][3]:
- Social Security numbers
- Medical records: your eye exam results, prescriptions, health history
- Health insurance information: policy numbers, group IDs, plan details
- Driver’s license numbers
- Dates of birth
- Names and addresses
- Financial documents and payroll reports: employee data too
- Corporate correspondence, contracts, and NDAs
That’s not just enough to open a credit card in your name. Medical records and health insurance data enable a different kind of fraud: medical identity theft. Someone uses your insurance to get prescriptions, treatments, or procedures. Their medical history gets mixed into your file. You don’t find out until your insurance denies coverage for a condition you don’t have, or a doctor makes a treatment decision based on someone else’s records.
Medical identity theft is harder to detect and harder to fix than financial fraud. There’s no equivalent of a credit freeze for your medical history.
The Timeline Problem
Pay attention to these dates:
- March 10, 2026: PayoutsKing publicly claims the breach on its leak site [1]
- April 17, 2026: Eyemart Express files disclosure with the Texas AG [3]
- May 2026: Affected individuals still not notified [2]
That’s almost two months between the attackers bragging about it online and the actual people whose Social Security numbers were stolen being told anything. As of early May, Eyemart Express has not publicly disclosed how many individuals are affected, has not announced credit monitoring or identity protection services, and has not issued a public statement [2].
Texas requires breach notification “as expeditiously as possible” and no later than 60 days after discovery. Whether Eyemart Express met that depends on when they claim to have “discovered” the breach: not when the attackers announced it, which is a convenient legal distinction that does nothing for the people whose data has been circulating on criminal forums for weeks.
Who Is PayoutsKing?
PayoutsKing is a relatively newer ransomware operation that surfaced on dark web forums in late 2025. Like most modern ransomware groups, they operate a double-extortion model: encrypt the victim’s systems, exfiltrate the data, then threaten to publish everything if the ransom isn’t paid [1].
The group maintains a leak site where they post victim names, data samples, and countdown timers. Eyemart Express appeared on that site on March 10. Whether the company paid, negotiated, or simply went silent hasn’t been disclosed. The full dataset has not been publicly dumped as of early May, which could mean negotiations are ongoing, a ransom was paid, or the group is waiting [1].
The Bigger Picture: Why Your Eye Doctor Is a Target
Most people don’t think of their eye doctor as holding high-value data. That’s exactly why optical retailers are attractive targets. They process medical exams (HIPAA-protected health information), run insurance claims (policy numbers, group IDs), verify identity (SSNs, driver’s licenses), and handle payments (financial data). All in one system.
Eyemart Express specifically markets itself as a one-stop shop: walk in, get an exam, pick your frames, walk out with glasses the same day. That convenience means one system stores everything: your health data, your identity documents, your insurance details, and your payment information.
Healthcare-adjacent retailers like optical chains, dental offices, and urgent care clinics often lack the security budgets of major hospital systems but hold the same categories of sensitive data. They’re the soft underbelly of healthcare data security.
Legal Fallout
At least three law firms have launched class action investigations against Eyemart Express:
- Migliaccio & Rathod LLP announced an investigation on May 1, 2026 [4]
- ClassAction.org began investigating on April 20, 2026 [3]
- Barnow and Associates, P.C. opened an investigation [5]
The core allegations are straightforward: Eyemart Express failed to adequately protect customer data, failed to promptly notify affected individuals, and may have violated state breach notification laws and HIPAA requirements for protecting medical information.
If the 435 GB claim is accurate and includes data from customers across the company’s 42-state footprint, this could become one of the larger retail healthcare breaches of 2026.
What You Should Do Right Now
If you’ve ever visited an Eyemart Express, Vision4Less, Visionmart Express, or Eyewear Express location, take these steps now. Don’t wait for a notification letter that may not come for weeks:
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). This is free and prevents anyone from opening accounts in your name. Call each bureau or do it online.
- Check your credit reports at annualcreditreport.com for any accounts you don’t recognize.
- Monitor your health insurance statements for claims you didn’t make. Medical identity theft shows up as unfamiliar charges, denied claims, or explanation-of-benefits notices for services you never received.
- Check your Social Security activity at ssa.gov for any suspicious changes or filings.
- Verify your driver’s license status with your state DMV: stolen license numbers can be used to create fake IDs.
- Watch for phishing: attackers who have your personal details craft convincing scam emails and texts. If you get a message claiming to be from Eyemart Express asking you to click a link or provide information, go directly to the company’s website instead.
The Bottom Line
You walked into an Eyemart Express to get your glasses prescription filled. You handed over your insurance card, your driver’s license, maybe your Social Security number for the insurance claim. Standard stuff. You didn’t sign up to have 435 gigabytes of your most sensitive personal data exfiltrated by a ransomware gang and held for ransom on the dark web.
And you definitely didn’t sign up to not be told about it for nearly two months.
Eyemart Express owes its customers three things: a clear disclosure of exactly what data was stolen, immediate notification to every affected individual, and free long-term identity and medical identity theft protection. So far, it has delivered none of the above.
Sources
- DeXpose: “PayoutsKing Strikes Optical Retailer Eyemart Express” (April 30, 2026)
- ClaimDepot: “Eyemart Express Data Breach: Social Security Numbers” (2026)
- ClassAction.org: “Eyemart Express Data Breach Reported; Lawyers Investigating” (April 2026)
- Migliaccio & Rathod LLP: “Eyemart Express Data Breach Investigation” (May 1, 2026)
- Barnow and Associates: “Eyemart Express Data Breach Investigation” (2026)
Published: May 3, 2026