Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CVS Pharmacy

CVS Pharmacy Vendor Cyber Rating & Cyber Score

cvs.co

CVS Pharmacy is a leading U.S. retail pharmacy and a subsidiary of CVS Health. CVS Pharmacy operates thousands of neighborhood locations across the United States, providing prescription medications, over‑the‑counter health products, and everyday essentials. Many CVS Pharmacy locations also offer convenient access to care through MinuteClinic, delivering walk‑in and scheduled healthcare services. Guided by a commitment to community health, CVS Pharmacy plays an important role in CVS Health’s purpose to help make health care more accessible, affordable, and connected. About CVS Health CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across


CVS Pharmacy A.I CyberSecurity Scoring

CVS Pharmacy
Company Information
Website:https://cvs.co/linkedinprofiles
Employees number:54,597
Number of followers:180,854
NAICS:44611
Industry Type:Retail Pharmacies
Homepage:cvs.co
CVS Pharmacy Risk Score (AI oriented)
Between 650 and 699
logo
CVS PharmacyRetail Pharmacies
Updated:
23/07/2026
698/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CVS Pharmacy Global Score (TPRM)
xxxx
logo
CVS PharmacyRetail Pharmacies
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CVS Pharmacy
CVS PharmacyWeak
Current Score
698B (WEAK)
01000
4 incidents
-51 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
700Before Incident
JULY 2026
749Before Incident
Breach
22 Jul 2026CVS Pharmacy
CVS Pharmacy: Chick-fil-a warns customers of data breach

CVS Pharmacy Data Breach Exposes Customer Information at Nearly 9,000 Locations

698After Incident
CRITICAL-51
CVS1784803103
CVS Pharmacy Data Breach Exposes Customer Information at Nearly 9,000 Locations CVS Pharmacy has disclosed a data breach affecting customers who purchased pet medications at approximately 9,000 of its nationwide locations. The incident raises concerns that sensitive customer information may have been exposed to unauthorized attackers. The breach was identified amid growing scrutiny over third-party risks in retail and pharmacy chains, where payment and personal data are frequently targeted. While CVS has not released specific details on the scope of the exposed data or the timeline of the breach, the company acknowledged that affected customers could include those who made transactions involving pet medications now widely available across its stores. The incident underscores the persistent vulnerabilities in supply chain and point-of-sale systems, particularly as retailers expand digital and in-store services. No further details on the attack vector or the number of impacted individuals have been confirmed. CVS continues to investigate the breach in coordination with cybersecurity experts.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive customer informationSystems Affected: Point-of-sale systems, supply chain systems
DATA BREACH
Type Of Data Compromised: Customer information, payment data, personal dataSensitivity Of Data: HighPersonally Identifiable Information: Likely
JUNE 2026
748Before Incident
MAY 2026
746Before Incident
APRIL 2026
746Before Incident
MARCH 2026
745Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
744Before Incident
DECEMBER 2025
737Before Incident
NOVEMBER 2025
737Before Incident
OCTOBER 2025
736Before Incident
SEPTEMBER 2025
735Before Incident
FEBRUARY 2022
725Before Incident
Breach
01 Feb 2022CVS Pharmacy
CVS Pharmacy

CVS Pharmacy Data Breach

661After Incident
CRITICAL-64
CVS1516522
CVS Pharmacy, Inc. suffered a cybersecurity incident that compromised the personal information of more than 6,000 consumers. An unauthorized party breached the company’s network servers and gained access to certain individuals’ names, addresses, and protected health information. CVS sent out data breach notification letters to those whose information was impacted in the breach.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesProtected Health InformationSystems Affected: Network Servers
DATA BREACH
NamesAddressesProtected Health InformationNumber Of Records Exposed: 6,000
JANUARY 2022
777Before Incident
Breach
06 Jan 2022CVS Pharmacy
CVS/pharmacy

CVS Pharmacy Data Breach via Password Spraying Attack

724After Incident
CRITICAL-53
CVS1015090725
On February 11, 2022, CVS Pharmacy experienced a data breach discovered on January 6, 2022, due to automated password spraying attacks targeting customer accounts. The incident potentially exposed sensitive personal information, including customer names, dates of birth, mailing addresses, email addresses, and limited prescription details. While the exact number of affected individuals remains undisclosed, the breach posed a significant risk of unauthorized access to customer data, raising concerns over identity theft, prescription fraud, or targeted phishing scams. The attack exploited weak or reused credentials, highlighting vulnerabilities in CVS’s authentication mechanisms. No ransomware was involved, but the compromise of prescription-related data—even if limited—intensified privacy and regulatory compliance risks under healthcare data protection laws like HIPAA. The breach underscored the need for stronger cybersecurity measures, such as multi-factor authentication (MFA) and monitoring for credential-stuffing attempts.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer NamesDates of BirthMailing AddressesEmail AddressesLimited Prescription InformationBrand Reputation Impact: Potential Negative Impact (Undisclosed Severity)Identity Theft Risk: High (Personal Information Exposed)
DATA BREACH
Personal InformationPrescription Information (Limited)Number Of Records Exposed: UnknownSensitivity Of Data: High (PII and Health-Related Data)Data Exfiltration: Likely (Unauthorized Access Confirmed)
JUNE 2014
788Before Incident
Breach
19 Jun 2014CVS Pharmacy
CVS Pharmacy, Inc.

CVS Pharmacy Data Breach

728After Incident
CRITICAL-60
CVS534072725
The California Office of the Attorney General reported that CVS Pharmacy, Inc. experienced a data breach involving unauthorized access to the CVSPhoto.com website between June 19, 2014, and July 14, 2015. The breach potentially affected customers' first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, and usernames and passwords, but not PIN numbers or photographic images. It is estimated that thousands of individuals' payment card information may have been compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
first and last namespayment card numbersexpiration datescard verification codesaddressesphone numbersemail addressesusernames and passwordsCVSPhoto.com websitePayment Information Risk: High
DATA BREACH
first and last namespayment card numbersexpiration datescard verification codesaddressesphone numbersemail addressesusernames and passwordsNumber Of Records Exposed: ThousandsSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CVS Pharmacy ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in July 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CVS Pharmacy's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on CVS Pharmacy's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CVS Pharmacy ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CVS Pharmacy's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?