Eye Buy Direct, Inc.
ent_0bfd322605a6ad800379e4c0
Disclosures
14
State AG · 9 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
756,322
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Eye Buy Direct, Inc.
- Normalized
- eye buy direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- eyebuydirect.com
Disclosure history (14)newest first
- South Carolina State AGas victim2019-10-25
EyeBuyDirect, Inc. notified customers that in June 2019, they learned of fraudulent credit card activity reported by 56 U.S. consumers between September 2018 and March 2019. The fraud was linked to transactions on the EyeBuyDirect website. Forensic investigators found signs of intrusion but could not confirm how or when the platform was breached or if data was taken. Affected data likely included personal details, prescription data, and payment card information. EyeBuyDirect offered one year of Experian IdentityWorks.
- Massachusetts State AGas victim2019-10-22
Eye Buy Direct, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-10-22. 24,882 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-10-21
Eye Buy Direct, Inc. notified New Hampshire residents of a security incident affecting purchases between Sept 10, 2018 and Sept 28, 2019. Forensic investigators found signs of intrusion but could not confirm data access. 4,847 NH residents were notified. Data potentially included PII, prescription info, and payment card details. Notifications mailed Oct 14, 2019.
- California State AGas victim2019-10-18
Eye Buy Direct, Inc. reported a data security breach to the California Attorney General. The breach occurred on September 1, 2018. The filing page lists the organization name and breach date but does not provide details on the nature of the breach, data types affected, or number of individuals impacted in the HTML summary. PDF attachments containing the consumer notification are linked but not parsed in this extraction.
- Oregon State AGas victim2019-10-18
Eye Buy Direct, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-10-18. The breach occurred during 9/1/2018 - 9/28/2019. The breach was discovered on 6/17/20199/17/2019. 756,322 individuals were affected. Notice was sent on 10/14/2019.
- Washington State AGas victim2019-10-15
Eye Buy Direct, Inc. notified Washington AG of a security incident affecting 17,031 state residents. Intrusions were detected in June 2019 following reports of credit card fraud. The breach window spanned September 2018 to September 2019. Investigators could not confirm data access, but notified customers who purchased during the window. Data potentially exposed included PII, prescription info, and payment card details. Remediation included forensic review and security updates.
- Montana State AGas victim2019-10-14
Eye Buy Direct, Inc. notified customers in Montana of a cybersecurity incident discovered in June 2019. The breach involved unauthorized access to the website, leading to fraudulent credit card activity. Affected data likely included names, addresses, prescription data, and payment card details. 356 U.S. consumers were affected. The company engaged forensic investigators and offered credit monitoring.
- Delaware State AGas victim2019-10-11
EyeBuyDirect, Inc. notified Delaware AG of a potential cybersecurity incident involving its e-commerce platform. The company learned in June 2019 that 356 consumers reported credit card fraud linked to transactions on the EyeBuyDirect website between September 2018 and March 2019. Forensic investigators found signs of intrusion but could not confirm how, when, or if data was accessed. Potentially compromised data includes PII, prescription data, and payment card details. The incident is contained, and the company has enhanced security protections.
- New Hampshire State AGas victim2019-03-21
Eye Buy Direct, Inc. experienced a security incident on February 24, 2019, where an unauthorized third party compromised a user account using stolen credentials and installed a keystroke logging script. This resulted in the exposure of payment card information and personal data for 8 New Hampshire residents. The company contained the incident the same day, removed the malicious code, and implemented additional security controls including HTTP authentication and device limitations.
- Massachusetts State AGas victim2019-03-20
Eye Buy Direct reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-20. 33 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-03-18
Eye Buy Direct, Inc. notified Montana residents of a cybersecurity incident on February 24, 2019. An unauthorized third party accessed payment card information, including card numbers and verification codes, for transactions conducted during a 10-hour window. The company blocked access, removed the capture mechanism, and mitigated the vulnerability. Affected individuals were offered complimentary identity theft monitoring and repair services through AllClear ID.
- Illinois State AGas victim2019-01-01
EYE BUY DIRECT, INC. filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-415). The register records the breach as discovered on September 1, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2015-10-16
Eye Buy Direct Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-16. 74 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2015-10-13
EyeBuyDirect, Inc. notified the New Hampshire Attorney General on October 13, 2015, of a data breach affecting 22 state residents. Unauthorized access occurred between Feb 9 and May 30, 2015, via hackers using a Russian IP. Exposed data included names, addresses, phone numbers, emails, credit card numbers, and CVV codes. Discovery was June 16, 2015. Forensic investigation confirmed the intrusion. Remediation included identity protection services for victims.