DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsPhishingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIdentity (basic)Government IDFinancial accountCredentialsHighActive

CVS Pharmacy, Inc.

bd_c170bb3c6ed5a8cb · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 1, 2015

Filed

Sep 14, 2015

To disclose

11 weeks

Affected

5,840state residents only

Linked

4 filings

Confidence

64%
Full breach record for CVS Pharmacy, Inc.9 incidents on file

CVS Pharmacy, Inc. disclosed that an illegal intrusion into third-party vendor PNI Digital Media's systems hosting CVSPhoto.com potentially exposed customer data including names, payment card details, and credentials between June 2014 and July 2015. CVS detected unusual activity in July 2015, took the site down, engaged forensic investigators, and offered one year of credit monitoring.

South Carolina clock SC CRA notice due11 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 395 days
discovery → filing · 11 weeks / 75 days

Jun 1, 2014

Begins

Jul 1, 2015

Discovered

Sep 14, 2015

Filed

vs. sector median

+3 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
New Hampshire State AGSep 10 · first
South Carolina State AG+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.