The Vermont Office of the Attorney General disclosed a data breach affecting Panorama Eyecare, discovered on June 5, 2024. The incident involved unauthorized access to the company’s internal network between May 22, 2023, and June 4, 2023, during which threat actors potentially exfiltrated personal information, including the full names of affected individuals. While the breach was confirmed, the exact number of impacted individuals remains undetermined, raising concerns about the scope of exposed data. The attack targeted internal systems, suggesting a compromise of employee or patient records, though no further details (e.g., financial data, medical histories, or other sensitive identifiers) were explicitly confirmed in the report. The delay in detection (nearly a year) highlights vulnerabilities in monitoring and response protocols, amplifying risks of downstream fraud or identity theft for those affected.
Source: https://ago.vermont.gov/document/2024-06-05-panorama-eyecare-data-breach-notice-consumers
TPRM report: https://www.rankiteo.com/company/panorama-eyecare
"id": "pan228090125",
"linkid": "panorama-eyecare",
"type": "Breach",
"date": "5/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Unknown',
'industry': 'Healthcare (Optometry)',
'location': 'Vermont, USA',
'name': 'Panorama Eyecare',
'type': 'Healthcare Provider'}],
'data_breach': {'data_exfiltration': 'Potential',
'number_of_records_exposed': 'Unknown',
'personally_identifiable_information': ['Full Names'],
'sensitivity_of_data': 'Moderate',
'type_of_data_compromised': ['Personal Information (full '
'names)']},
'date_publicly_disclosed': '2024-06-05',
'description': 'The Vermont Office of the Attorney General reported a data '
'breach involving Panorama Eyecare. The breach involved '
'unauthorized access to Panorama’s internal network between '
'May 22, 2023, and June 4, 2023, which may have led to the '
'access and removal of personal information, including full '
'names of individuals affected. The exact number of '
'individuals affected is unknown.',
'impact': {'data_compromised': ['Personal Information (including full names)'],
'identity_theft_risk': 'Potential',
'systems_affected': ['Internal Network']},
'references': [{'date_accessed': '2024-06-05',
'source': 'Vermont Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Vermont Office of the '
'Attorney General']},
'title': 'Panorama Eyecare Data Breach (2023)',
'type': 'Data Breach'}