In Dec 2018 I purchased a pair of prescription glasses from EyeBuyDirect (not hyperlinked intentionally). On Oct 16th 2019 (yesterday), I received a letter from EyeBuyDirect in Austin, TX indicating that they had been the “victim” of a data breach.
Not to worry, the perpetrators only managed to “potentially” compromise my name, address, e-mail address, eyeglass prescription information, credit card number, credit card expiration date and credit card security code….pretty much everything.
This sort of letter now seems to be common place and just last month I received another such letter from Café Press (yes I used to sell mybeerbuzz T-Shirts) announcing another data breach on their site.
What’s particularly frustrating with EyeBuyDirect is that they were aware of the breach in June 2019, yet they waited over 4-months to notify me or anyone else. As you can see in the letter above, rather than providing free credit monitoring for a year (like Café Press), EyeBuyDirect simply recommended we keep an eye on the credit card we used to buy from EyeBuyDirect.
Of course it would have been nice to have been keeping an eye on my credit card for the last 4-months when a fraudulent transaction would be most likely to occur. Instead EyeBuyDirect spent that time working to patch the issues that caused the breach rather than protecting my credit card or personal information.
What’s more frustrating is that EyeBuyDirect also had data breach issues in March 2019 and in Oct 2015 as well, and yet here we are again.
After this experience, I’m left with several conclusions.
- EyeBuyDirect isn’t concerned with protecting it’s customer information enough to notify us in a timely manner of an identified breach.
- EyeBuyDirect won’t be taking responsibility for the breach by providing a year’s worth of free credit monitoring (the very LEAST they can do).
- This isn’t the first time EyeBuyDirect has been breached so it likely won’t be the last.
- I will no longer be purchasing anything from EyeBuyDirect and you shouldn’t either.
We speak with our wallets and in this case, there are plenty of other on-line prescription eyewear sites to choose from. I can see clearly now that EyeBuyDirect has been myopic in their how they care for their customers, so I’ll be buying elsewhere.
I got the same letter in the mail... as customer we have to do all the legwork to protect our PII. They should be held liable for their ineptness
ReplyDeleteI also received a letter from eye buy direct. We shoul start a class action against them
ReplyDeletei just realized that my credits were gone, customer service didn't help at all. won't buy anything from them again.
ReplyDelete