HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
CVS Pharmacy, Inc.
bd_f5443285e06537f2 · schema v1 · pii pii-v1
Full breach record for CVS Pharmacy, Inc. →CVS Pharmacy disclosed a security incident involving password spraying attacks against customer accounts on CVS.com. The attack occurred between January 6, 2022, and January 25, 2022. The incident resulted in the unauthorized access of customer names, dates of birth, mailing addresses, email addresses, and limited prescription information. No financial or Social Security numbers were compromised. CVS reset passwords for affected accounts and implemented additional website security measures.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550888
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 11, 2022
- Raw hash
- 9974834f2f47bd533ad49963ad036901bd77e71fc8515c29c78b0ae0c1335f8e
Reporting entity
- Name
- CVS Pharmacy, Inc.norm: cvs pharmacy
- Domain
- cvs.com
Victim entity
- Name
- CVS Pharmacy, Inc.norm: cvs pharmacy
- Domain
- cvs.com
Incident
- Discovered
- Jan 25, 2022
- Materiality determined
- Feb 10, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1110 Brute Force
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.