Data breach · 2025
The Frame & Optic data breach, explained
Frame & Optic (frameandoptic.com) was breached on January 16, 2025, exposing 16 thousand accounts. Here is exactly what leaked, what it means, and the order to fix things in.
15,678 accounts · 4 data classes · verified record
The numbers
What the record shows
What leaked
4 kinds of data were exposed
The universal account key. Exposed addresses get targeted with credential-stuffing and phishing that name the breached site to look legitimate.
Coarse location history attached to your identity.
Real names turn generic spam into convincing, personally addressed phishing.
Enables SIM-swap attempts and smishing, and links this account to every other one that knows the number.
In this order
What to do now
Rotate the Frame & Optic password anyway
Passwords were not in this record, but leaked profile data makes targeted phishing against this account more convincing, and rotation costs one minute.
Kill the reuse, which is the real damage
Every account sharing that password is now one automated attempt from gone. This is the tedious part, and it is the part Repass automates: it finds the accounts and runs each site's official reset flow for you.
Scan your email for the rest of your exposure
Run the free breach scan on the address you use most. Frame & Optic is one breach; the median active email address appears in several, and what to fix first depends on the full picture.
Turn on two-factor authentication
A leaked password with a second factor in front of it is a locked door with a stolen key that no longer fits. Prefer an authenticator app over texted codes where the service offers the choice.
Questions
Frame & Optic breach FAQ
Was my Frame & Optic account affected by the breach?
The record covers 15,678 accounts. The quick way to check is a breach scan against your own email address, which searches this breach and hundreds of others at once. Repass runs one free on its homepage.
What should I change first after the Frame & Optic breach?
Passwords were not in this record, so the urgent risk is targeted phishing that uses the leaked details to sound legitimate. Treat unexpected Frame & Optic-branded email with suspicion, and rotate the password anyway if it is one you reuse.
Is changing my Frame & Optic password enough?
Only if that password lived nowhere else. Credential-stuffing takes leaked email-and-password pairs and tries them on banks, mailboxes and stores at machine speed, so the reused copies matter more than the original. A reused password is a breach of every account that shares it.
Where does this breach data come from?
From the public index maintained by Have I Been Pwned, which verifies breaches before listing them. This page renders the structured record: dates, account count and exposed data classes.
How do I find out what else has leaked about me?
Run a breach scan on your email address. It returns every verified breach that lists the address, which is the honest starting point for deciding what to reset first. Repass then resets the passwords for you, one official flow at a time, and seals each new one in an encrypted vault.
More records
Other major breaches
After the breach
Every reused password, replaced for you.
Get Started3-day free trial · strong unique passwords · encrypted vault