OCUCO LIMITED
bd_95457d0ff244ea48 · schema v1 · pii pii-v1
Full breach record for OCUCO LIMITED →2 incidents on fileOcuco, an eye care technology company, disclosed a cybersecurity incident where an unauthorized actor accessed non-production servers between March 28 and April 1, 2025, exploiting a newly discovered vulnerability in third-party software. The incident exposed PHI and PII of 24,833 Washington residents. Ocuco notified the Washington AG on July 11, 2025, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 28, 2025
Begins
Apr 1, 2025
Discovered
Jul 11, 2025
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_834af0e66c3c8c792025-07-11Candidate
- California State AGbd_d064c92f5f9d40172025-07-11Verified
- Texas State AGbd_1a8b007fe58ca0e42025-07-15 · +4dVerified
- Oregon State AGbd_9ce21f0d45a154ff2025-07-28 · +17dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 11 (MT), last Jul 28 (OR) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.