Company Details
cvs-pharmacy
53,044
173,748
3254
cvshealth.com
0
CVS_3306534
In-progress

CVS Pharmacy Company CyberSecurity Posture
cvshealth.comCVS Pharmacy is America’s leading retail pharmacy with more than 9,600 locations nationwide. For more than 50 years, CVS Pharmacy has offered customers the products and services they need to stay on their path to better health. In addition to our pharmacies, our stores feature on-trend beauty departments, photo labs and general merchandise. About CVS Health CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues – including more than 40,000 physicians, pharmacists, nurses and nurse practitioners. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by improving access, lowering costs and being a trusted partner for every meaningful moment of health. And we do it all with heart, each and every day. Please note: We reserve the right to delete any posts that contain personal health information (PHI), personally identifiable information (PII), Sensitive Personal Information (SPI) or are approaching HIPAA violations. We reserve the right to remove comments that are discriminatory, harassing, bullying, threatening, defamatory, or unlawful.
Company Details
cvs-pharmacy
53,044
173,748
3254
cvshealth.com
0
CVS_3306534
In-progress
Between 700 and 749

CVS Pharmacy Global Score (TPRM)XXXX

Description: CVS Pharmacy, Inc. suffered a cybersecurity incident that compromised the personal information of more than 6,000 consumers. An unauthorized party breached the company’s network servers and gained access to certain individuals’ names, addresses, and protected health information. CVS sent out data breach notification letters to those whose information was impacted in the breach.
Description: The California Office of the Attorney General reported that CVS Pharmacy, Inc. experienced a data breach involving unauthorized access to the CVSPhoto.com website between June 19, 2014, and July 14, 2015. The breach potentially affected customers' first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, and usernames and passwords, but not PIN numbers or photographic images. It is estimated that thousands of individuals' payment card information may have been compromised.
Description: On February 11, 2022, CVS Pharmacy experienced a data breach discovered on January 6, 2022, due to automated **password spraying** attacks targeting customer accounts. The incident potentially exposed sensitive personal information, including **customer names, dates of birth, mailing addresses, email addresses, and limited prescription details**. While the exact number of affected individuals remains undisclosed, the breach posed a significant risk of unauthorized access to customer data, raising concerns over identity theft, prescription fraud, or targeted phishing scams. The attack exploited weak or reused credentials, highlighting vulnerabilities in CVS’s authentication mechanisms. No ransomware was involved, but the compromise of prescription-related data—even if limited—intensified privacy and regulatory compliance risks under healthcare data protection laws like **HIPAA**. The breach underscored the need for stronger cybersecurity measures, such as multi-factor authentication (MFA) and monitoring for credential-stuffing attempts.


No incidents recorded for CVS Pharmacy in 2025.
No incidents recorded for CVS Pharmacy in 2025.
No incidents recorded for CVS Pharmacy in 2025.
CVS Pharmacy cyber incidents detection timeline including parent company and subsidiaries

CVS Pharmacy is America’s leading retail pharmacy with more than 9,600 locations nationwide. For more than 50 years, CVS Pharmacy has offered customers the products and services they need to stay on their path to better health. In addition to our pharmacies, our stores feature on-trend beauty departments, photo labs and general merchandise. About CVS Health CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues – including more than 40,000 physicians, pharmacists, nurses and nurse practitioners. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by improving access, lowering costs and being a trusted partner for every meaningful moment of health. And we do it all with heart, each and every day. Please note: We reserve the right to delete any posts that contain personal health information (PHI), personally identifiable information (PII), Sensitive Personal Information (SPI) or are approaching HIPAA violations. We reserve the right to remove comments that are discriminatory, harassing, bullying, threatening, defamatory, or unlawful.

EMS is the leading pharmaceutical company in Brazil. Established since 45 years and with 100% national capital, the company has two industrial plants strategically placed in São Bernardo do Campo and Hortolândia, in the state of São Paulo. With a work based on daring, simplicity, excellence and res

A consumer-led global pharmaceutical company, creating healthy doses of life since 1949. When you operate in an industry like pharmaceuticals, your work goes way beyond creating ‘products for customers’. It is different from any other domain – there lies a higher sense of responsibiliti and a need

Founded to serve health 70 years ago, Servier is a global pharmaceutical group governed by a non-profit Foundation that aspires to make a meaningful social impact for patients and for a sustainable world. The Group’s unique governance model preserves its independence and means it can fully serve its

Hetero is a research based global pharmaceutical company focused on development, manufacturing and marketing of Active Pharmaceutical Ingredients (APIs), Intermediate Chemicals & Finished Dosages. Ever since its establishment in 1993, Hetero showed a tradition of excellence and deep sense of commitm

At MSD, known as Merck & Co., Inc., Rahway, NJ, USA in the United States and Canada, we are unified around our purpose: We use the power of leading-edge science to save and improve lives around the world. For more than 130 years, we have brought hope to humanity through the development of important

Cipla is a leading global pharmaceutical company trusted by healthcare professionals and patients across the world since 1935. A compassionate approach to healthcare that goes beyond the pursuit of profit and growth has been the force impelling Cipla’s history over the years. Our credo and our purp

Torrent Pharma, with annual revenues of more than Rs 10,700 crores, is the flagship Company of the Torrent Group, with group revenues of Rs 41,000 crores. It is ranked 5th in the Indian Pharma Market and is among the Top 5 in the therapeutic segments of Cardiovascular (CV), Central Nervous System (C

Glenmark Pharmaceuticals Limited is a research-led, global organization committed to enriching lives. Innovation is deeply embedded in Glenmark’s culture; it is how we differentiate ourselves in our key markets and create greater value for our stakeholders. In our journey of innovation over the pa

The Zydus Group with an overarching purpose of empowering people with freedom to live healthier and more fulfilled lives, is an innovative, global life-sciences company that discovers, develops, manufactures, and markets a broad range of healthcare therapies. The group employs over 27000 people worl
.png)
A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach has been allowed to proceed after...
In 2023, 725 data breaches were reported to OCR and across those breaches, more than 133 million records were exposed or impermissibly disclosed.
CVS Health's 2025 Rx Report highlights key community pharmacy trends, showing how patient needs, workforce pressures and sustainable care...
Washington — Karen Lynch, CEO of pharmacy giant CVS Health, spoke this week about the decision to carry the pill for the first time in an...
CVS Health is facing a probe into potential HIPAA violations related to the alleged use of patient data for lobbying purposes to prevent the...
Retail pharmacy operators face an array of challenges beyond PBM reform, which many observers say remains the single biggest obstacle to...
The pending sale of millions of customer health records as part of Rite Aid Corp. 's bankruptcy proceedings is putting a spotlight on data security protections.
DALLAS (KTVT) - The family of a security guard fatally shot while confronting shoplifters at a CVS Pharmacy in Dallas is struggling with raw...
CVS Health has announced that all commercial prescriptions dispensed through its pharmacies will be now contracted through the company's CostVantage...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of CVS Pharmacy is https://cvs.co/linkedinprofiles.
According to Rankiteo, CVS Pharmacy’s AI-generated cybersecurity score is 737, reflecting their Moderate security posture.
According to Rankiteo, CVS Pharmacy currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, CVS Pharmacy is not certified under SOC 2 Type 1.
According to Rankiteo, CVS Pharmacy does not hold a SOC 2 Type 2 certification.
According to Rankiteo, CVS Pharmacy is not listed as GDPR compliant.
According to Rankiteo, CVS Pharmacy does not currently maintain PCI DSS compliance.
According to Rankiteo, CVS Pharmacy is not compliant with HIPAA regulations.
According to Rankiteo,CVS Pharmacy is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
CVS Pharmacy operates primarily in the Pharmaceutical Manufacturing industry.
CVS Pharmacy employs approximately 53,044 people worldwide.
CVS Pharmacy presently has no subsidiaries across any sectors.
CVS Pharmacy’s official LinkedIn profile has approximately 173,748 followers.
CVS Pharmacy is classified under the NAICS code 3254, which corresponds to Pharmaceutical and Medicine Manufacturing.
Yes, CVS Pharmacy has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/cvs-pharmacy.
Yes, CVS Pharmacy maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cvs-pharmacy.
As of December 05, 2025, Rankiteo reports that CVS Pharmacy has experienced 3 cybersecurity incidents.
CVS Pharmacy has an estimated 5,316 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with data breach notification letters sent to affected individuals, and communication strategy with public disclosure via california office of the attorney general..
Title: CVS Pharmacy Data Breach
Description: CVS Pharmacy, Inc. suffered a cybersecurity incident that compromised the personal information of more than 6,000 consumers. An unauthorized party breached the company’s network servers and gained access to certain individuals’ names, addresses, and protected health information. CVS sent out data breach notification letters to those whose information was impacted in the breach.
Type: Data Breach
Attack Vector: Unauthorized Access
Title: CVS Pharmacy Data Breach
Description: The California Office of the Attorney General reported that CVS Pharmacy, Inc. experienced a data breach involving unauthorized access to the CVSPhoto.com website between June 19, 2014, and July 14, 2015. The breach potentially affected customers' first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, and usernames and passwords, but not PIN numbers or photographic images. It is estimated that thousands of individuals' payment card information may have been compromised.
Date Detected: 2015-07-14
Type: Data Breach
Attack Vector: Unauthorized Access
Title: CVS Pharmacy Data Breach via Password Spraying Attack
Description: The California Office of the Attorney General reported a data breach involving CVS Pharmacy, discovered on January 6, 2022. The breach resulted from automated attempts to log in to customer accounts through password spraying, potentially compromising personal information such as customer names, dates of birth, mailing addresses, email addresses, and limited prescription information. The number of affected individuals is unknown.
Date Detected: 2022-01-06
Date Publicly Disclosed: 2022-02-11
Type: Data Breach
Attack Vector: Password Spraying
Vulnerability Exploited: Weak or Reused Credentials
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Customer Account Credentials (Password Spraying).

Data Compromised: Names, Addresses, Protected health information
Systems Affected: Network Servers

Data Compromised: First and last names, Payment card numbers, Expiration dates, Card verification codes, Addresses, Phone numbers, Email addresses, Usernames and passwords
Systems Affected: CVSPhoto.com website
Payment Information Risk: High

Data Compromised: Customer names, Dates of birth, Mailing addresses, Email addresses, Limited prescription information
Brand Reputation Impact: Potential Negative Impact (Undisclosed Severity)
Identity Theft Risk: High (Personal Information Exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Addresses, Protected Health Information, , First And Last Names, Payment Card Numbers, Expiration Dates, Card Verification Codes, Addresses, Phone Numbers, Email Addresses, Usernames And Passwords, , Personal Information, Prescription Information (Limited) and .

Entity Name: CVS Pharmacy, Inc.
Entity Type: Company
Industry: Healthcare
Customers Affected: 6,000

Entity Name: CVS Pharmacy, Inc.
Entity Type: Company
Industry: Pharmacy
Location: California
Customers Affected: Thousands

Entity Name: CVS Pharmacy
Entity Type: Corporation
Industry: Healthcare/Pharmacy
Location: United States (Primarily California)
Customers Affected: Unknown

Communication Strategy: Data breach notification letters sent to affected individuals

Communication Strategy: Public Disclosure via California Office of the Attorney General

Type of Data Compromised: Names, Addresses, Protected health information
Number of Records Exposed: 6,000

Type of Data Compromised: First and last names, Payment card numbers, Expiration dates, Card verification codes, Addresses, Phone numbers, Email addresses, Usernames and passwords
Number of Records Exposed: Thousands
Sensitivity of Data: High
Personally Identifiable Information: Yes

Type of Data Compromised: Personal information, Prescription information (limited)
Number of Records Exposed: Unknown
Sensitivity of Data: High (PII and Health-Related Data)
Data Exfiltration: Likely (Unauthorized Access Confirmed)

Regulations Violated: Potential HIPAA (Health Insurance Portability and Accountability Act) Violations, California Consumer Privacy Act (CCPA) Notification Requirements,
Regulatory Notifications: California Office of the Attorney General

Source: California Office of the Attorney General

Source: California Office of the Attorney General
Date Accessed: 2022-02-11
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General, and Source: California Office of the Attorney GeneralDate Accessed: 2022-02-11.

Investigation Status: Disclosed; Further Details Unclear
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data breach notification letters sent to affected individuals and Public Disclosure via California Office of the Attorney General.

Entry Point: Customer Account Credentials (Password Spraying)
High Value Targets: Customer Personal and Prescription Data
Data Sold on Dark Web: Customer Personal and Prescription Data

Root Causes: Weak Authentication Mechanisms (Susceptibility to Password Spraying)
Most Recent Incident Detected: The most recent incident detected was on 2015-07-14.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-02-11.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Addresses, Protected Health Information, , first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, usernames and passwords, , Customer Names, Dates of Birth, Mailing Addresses, Email Addresses, Limited Prescription Information and .
Most Significant System Affected: The most significant system affected in an incident was CVSPhoto.com website.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were first and last names, Protected Health Information, Names, Customer Names, expiration dates, usernames and passwords, Email Addresses, addresses, Addresses, payment card numbers, Mailing Addresses, phone numbers, Dates of Birth, email addresses, card verification codes and Limited Prescription Information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 6.0M.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Disclosed; Further Details Unclear.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Customer Account Credentials (Password Spraying).
.png)
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.
Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If they contain HTML tags, they will be rendered (after some escaping using quotes and textarea tags).
SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files in the web UI. This vulnerability is fixed in 2025.102.
Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the local tid to whatever transition matched the current blockHash before knowing whether that batch would actually be verified. When the loop later broke (e.g., cooldown window not yet passed or transition invalidated), the function still wrote that newer tid into batches[lastVerifiedBatchId].verifiedTransitionId after decrementing batchId. Result: the last verified batch could end up pointing at a transition index from the next batch (often zeroed), corrupting the verified chain pointer.
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.