CVS Pharmacy, Inc.
bd_0146674d7aa449bb · schema v1 · pii pii-v1
Full breach record for CVS Pharmacy, Inc. →9 incidents on fileCVS Pharmacy, Inc. notified the NH Attorney General of a breach at third-party vendor PNI Digital Media affecting CVSPhoto.com. Unauthorized access occurred between June 2014 and July 2015, exposing payment card data, names, and credentials. Approximately 2,493 NH residents were affected. CVS disabled the site, engaged forensic investigators, and provided 12 months of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2014
Begins
Jul 1, 2015
Discovered
Sep 10, 2015
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_8534ceb654eebac52015-09-11 · +1dVerified
- California State AGbd_fc4af90e78d486c12015-09-11 · +1dCandidate
- South Carolina State AGbd_c170bb3c6ed5a8cb2015-09-14 · +4dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.