CVS Pharmacy disclosed a security incident involving password spraying attacks against customer accounts on CVS.com. The attack occurred between January 6, 2022, and January 25, 2022. The incident resulted in the unauthorized access of customer names, dates of birth, mailing addresses, email addresses, and limited prescription information. No financial or Social Security numbers were compromised. CVS reset passwords for affected accounts and implemented additional website security measures.