CVS Pharmacy, Inc. disclosed a breach affecting its CVSPhoto.com website, managed by third-party vendor PNI Digital Media. The incident occurred between June 19, 2014, and July 14, 2015, involving unauthorized access to PNI's systems. Affected data included names, payment card numbers, expiration dates, CVVs, addresses, phone numbers, emails, and login credentials. CVS disabled the site, engaged forensic investigators, and provided one year of free credit monitoring via Experian to affected customers.