Eyemart Express
bd_aecf969a43db5794 · schema v1 · pii pii-v1
Full breach record for Eyemart Express →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Payoutsking on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Eyemart Express is a United States-based retail optical chain specializing in prescription eyeglasses and contact lenses. Founded in 1990 and headquartered in Farmers Branch, Texas, the company operates hundreds of stores across the country. It offers eye exams, frames, and lenses with an emphasis on fast turnaround times. Eyemart Express competes in the optical retail industry alongside brands like LensCrafters and Visionworks.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 19, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Illinois State AGbd_549b93b9611b740e2026-07-01 · +132dVerified
- Nebraska State AGbd_4a6aff08452307852026-07-15 · +146dVerified by operator
- Texas State AGbd_97f5a5a1fc51dff72026-07-21 · +152dVerified by operator
- Washington State AGbd_5544bd65d17f4cc02026-07-24 · +155dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 166d gap
- New Hampshire State AGbd_a3362723e61aff662026-07-24 · +155dVerified by operator
- California State AGbd_ab90ebd336b9aa432026-07-24 · +155dVerified
- Massachusetts State AGbd_b48fa3831b0e2c182026-07-24 · +155dVerified
- Iowa State AGbd_b78b3c271d2c47532026-07-24 · +155dVerified
- Vermont State AGbd_f4c0a2dcf0b13d892026-07-24 · +155dVerified
- Oregon State AGbd_6f51a6aea30c468c2026-08-04 · +166dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Feb 19, last Aug 4 (OR) — a 166-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
payoutsking
According to ransomware.live, PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.