OCUCO LIMITED
bd_d064c92f5f9d4017 · schema v1 · pii pii-v1
Full breach record for OCUCO LIMITED →2 incidents on fileOcuco Ltd., an eye care technology company, experienced a data breach involving protected health information (PHI) and personal information. An unauthorized actor accessed non-production servers between March 28 and April 1, 2025, exploiting a vulnerability in third-party software. Files were copied from one server. Ocuco discovered the incident on April 1, 2025, after a dark web posting. The company patched the vulnerability, engaged forensic experts, and is offering 24 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 28, 2025
Begins
Apr 1, 2025
Discovered
Jul 11, 2025
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_834af0e66c3c8c792025-07-11Candidate
- Washington State AGbd_95457d0ff244ea482025-07-11Verified
- Texas State AGbd_1a8b007fe58ca0e42025-07-15 · +4dVerified
- Oregon State AGbd_9ce21f0d45a154ff2025-07-28 · +17dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jul 11 (MT), last Jul 28 (OR) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.