CVS Pharmacy, Inc.
bd_f5443285e06537f2 · schema v1 · pii pii-v1
Full breach record for CVS Pharmacy, Inc. →9 incidents on fileCVS Pharmacy reported a password spraying incident targeting its retail website (www.CVS.com). Automated attempts used common passwords to acquire valid account credentials. Internal systems were not impacted. Affected data included first name, last name, date of birth, mailing address, email address, and limited prescription information (medication name, last fill date). No SSN or financial data was involved. Passwords for impacted accounts were reset.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 6, 2022
Begins
Feb 11, 2022
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_e034d1beb1c5e5fd2022-02-11Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.