Ocuco, a company that builds software used by eye care providers, has notified patients that an unauthorized actor gained access to its systems earlier this year. Ocuco first learned of the incident on April 1, 2025, after someone claimed on the dark web to have stolen data from its environment. An investigation by outside cybersecurity experts found that between March 28 and April 1, 2025, the unauthorized actor accessed two non-production servers, and that files were copied from one of those servers between March 30 and April 1, 2025. Ocuco says the intrusion was made possible by a newly discovered vulnerability in third-party software it uses, one that had not been disclosed to the company in time to prevent the attack. This falls into the category of a hacking or system intrusion, meaning someone actively broke into Ocuco’s systems rather than the data being lost or misdirected by accident.
Because Ocuco provides software services to eye care providers, the information involved relates to patients of those providers rather than direct customers of Ocuco. The company completed its review of the affected files on July 3, 2025, and began mailing notification letters to individuals it could identify and locate addresses for. The letter does not state how many people were affected in total.
What information was exposed?
- Full name
- Protected health information connected to the provision of your eye care (the letter does not spell out every specific data element involved, so if you received a letter, check the enclosed personal details section for the exact items listed for you)
Ocuco is offering affected individuals complimentary Single Bureau Credit Monitoring, Credit Report, and Credit Score services for 24 months at no cost, delivered through Cyberscout, a TransUnion company. To enroll, log on to www.mytrueidentity.com and enter the unique code included in your individual letter. You must enroll within 90 days of the date of the letter (July 11, 2025) to receive these services.
What should you do now?
- Enroll in the free credit monitoring offer before the 90-day deadline using the code in your letter, since this service is provided at no cost to you.
- Because protected health information was involved, watch for unusual activity not just on financial accounts but also on insurance statements, explanation of benefits notices, and any unfamiliar medical bills.
- Consider placing a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion; freezes are free and prevent new accounts from being opened in your name.
- Review your free annual credit reports at www.annualcreditreport.com and look for accounts or inquiries you don’t recognize.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, such as on the dark web where this incident was first discovered.
- Keep a copy of the notification letter and any correspondence with Ocuco, in case you need to reference it later when disputing fraudulent activity.
- If you believe your information has been misused, report it to the FTC at www.ftc.gov/bcp/edu/microsites/idtheft/ or 1-877-IDTHEFT (438-4338).
If you have questions, Ocuco can be reached at 1-833-397-3848, Monday through Friday between 8:00 a.m. and 8:00 p.m. Eastern Time.