HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
OCUCO LIMITED
bd_d064c92f5f9d4017 · schema v1 · pii pii-v1
Full breach record for OCUCO LIMITED →Ocuco Ltd., an eye care technology company, experienced a data breach involving protected health information (PHI) and personal information. An unauthorized actor accessed non-production servers between March 28 and April 1, 2025, exploiting a vulnerability in third-party software. Files were copied from one server. Ocuco discovered the incident on April 1, 2025, after a dark web posting. The company patched the vulnerability, engaged forensic experts, and is offering 24 months of credit monitoring to affected individuals.
California clockDiscovered Apr 1, 2025 → Notified Jul 11, 2025101d ✗ CA 60-day late14 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_834af0e66c3c8c79Montana State AGfiled 2025-07-11Candidate
- bd_95457d0ff244ea48Washington State AGfiled 2025-07-11Verified
- bd_1a8b007fe58ca0e4Texas State AGfiled 2025-07-15(4d gap)Verified
- bd_9ce21f0d45a154ffOregon State AGfiled 2025-07-28(17d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605301
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2025
- Raw hash
- dc0303be764d3b4fd2f5039d2cc64bd4e1441bf544a90d88c76d1c3359b35c98
Reporting entity
- Name
- OCUCO LIMITEDnorm: ocuco
- Domain
- ocuco.com
Victim entity
- Name
- OCUCO LIMITEDnorm: ocuco
- Domain
- ocuco.com
Incident
- Discovered
- Apr 1, 2025
- Materiality determined
- —
- Notification sent
- Jul 11, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 14 weeks(101 days from discovery to filing)
- Compliance flags
- CA 60-day late · 101dLeak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 1, 2025→ Notified: Jul 11, 2025101d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.