DisclosureLens
HackingRetail & ConsumerTechnologyRetailDelayed DiscoveryCustomer Data InvolvedAuthenticationFinancial accountFinancial credentialsHealth (basic)Identity (basic)PHIMediumContained

Eye Buy Direct, Inc.

bd_7af7bf0034986af6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 1, 2019

Filed

Oct 15, 2019

To disclose

19 weeks

Affected

17,031state residents only

Linked

8 filings

Confidence

69%
Full breach record for Eye Buy Direct, Inc.4 incidents on file

Eye Buy Direct, Inc. notified Washington AG of a security incident affecting 17,031 state residents. Intrusions were detected in June 2019 following reports of credit card fraud. The breach window spanned September 2018 to September 2019. Investigators could not confirm data access, but notified customers who purchased during the window. Data potentially exposed included PII, prescription info, and payment card details. Remediation included forensic review and security updates.

Incident timeline

undetected · 273 days
discovery → filing · 19 weeks / 136 days

Sep 1, 2018

Begins

Jun 1, 2019

Discovered

Oct 15, 2019

Filed

vs. sector median

+12 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 10d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Oct 11 (DE), last Oct 25 (SC) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.