Company Details
cvs-pharmacy
53,044
173,748
3254
cvshealth.com
0
CVS_3306534
In-progress

CVS Pharmacy Company CyberSecurity Posture
cvshealth.comCVS Pharmacy is America’s leading retail pharmacy with more than 9,600 locations nationwide. For more than 50 years, CVS Pharmacy has offered customers the products and services they need to stay on their path to better health. In addition to our pharmacies, our stores feature on-trend beauty departments, photo labs and general merchandise. About CVS Health CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues – including more than 40,000 physicians, pharmacists, nurses and nurse practitioners. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by improving access, lowering costs and being a trusted partner for every meaningful moment of health. And we do it all with heart, each and every day. Please note: We reserve the right to delete any posts that contain personal health information (PHI), personally identifiable information (PII), Sensitive Personal Information (SPI) or are approaching HIPAA violations. We reserve the right to remove comments that are discriminatory, harassing, bullying, threatening, defamatory, or unlawful.
Company Details
cvs-pharmacy
53,044
173,748
3254
cvshealth.com
0
CVS_3306534
In-progress
Between 700 and 749

CVS Pharmacy Global Score (TPRM)XXXX

Description: CVS Pharmacy, Inc. suffered a cybersecurity incident that compromised the personal information of more than 6,000 consumers. An unauthorized party breached the company’s network servers and gained access to certain individuals’ names, addresses, and protected health information. CVS sent out data breach notification letters to those whose information was impacted in the breach.
Description: The California Office of the Attorney General reported that CVS Pharmacy, Inc. experienced a data breach involving unauthorized access to the CVSPhoto.com website between June 19, 2014, and July 14, 2015. The breach potentially affected customers' first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, and usernames and passwords, but not PIN numbers or photographic images. It is estimated that thousands of individuals' payment card information may have been compromised.
Description: On February 11, 2022, CVS Pharmacy experienced a data breach discovered on January 6, 2022, due to automated **password spraying** attacks targeting customer accounts. The incident potentially exposed sensitive personal information, including **customer names, dates of birth, mailing addresses, email addresses, and limited prescription details**. While the exact number of affected individuals remains undisclosed, the breach posed a significant risk of unauthorized access to customer data, raising concerns over identity theft, prescription fraud, or targeted phishing scams. The attack exploited weak or reused credentials, highlighting vulnerabilities in CVS’s authentication mechanisms. No ransomware was involved, but the compromise of prescription-related data—even if limited—intensified privacy and regulatory compliance risks under healthcare data protection laws like **HIPAA**. The breach underscored the need for stronger cybersecurity measures, such as multi-factor authentication (MFA) and monitoring for credential-stuffing attempts.


No incidents recorded for CVS Pharmacy in 2025.
No incidents recorded for CVS Pharmacy in 2025.
No incidents recorded for CVS Pharmacy in 2025.
CVS Pharmacy cyber incidents detection timeline including parent company and subsidiaries

CVS Pharmacy is America’s leading retail pharmacy with more than 9,600 locations nationwide. For more than 50 years, CVS Pharmacy has offered customers the products and services they need to stay on their path to better health. In addition to our pharmacies, our stores feature on-trend beauty departments, photo labs and general merchandise. About CVS Health CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues – including more than 40,000 physicians, pharmacists, nurses and nurse practitioners. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by improving access, lowering costs and being a trusted partner for every meaningful moment of health. And we do it all with heart, each and every day. Please note: We reserve the right to delete any posts that contain personal health information (PHI), personally identifiable information (PII), Sensitive Personal Information (SPI) or are approaching HIPAA violations. We reserve the right to remove comments that are discriminatory, harassing, bullying, threatening, defamatory, or unlawful.


The Menarini Group is a leading international pharmaceutical and diagnostics company, present in 140 countries worldwide, with a turnover of 4,37 Billion euro and more than 17,000 employees. With 9 centers for Research & Development, Menarini’s products are present in the most important therapeutic

Torrent Pharma, with annual revenues of more than Rs 10,700 crores, is the flagship Company of the Torrent Group, with group revenues of Rs 41,000 crores. It is ranked 5th in the Indian Pharma Market and is among the Top 5 in the therapeutic segments of Cardiovascular (CV), Central Nervous System (C

Hetero is a research based global pharmaceutical company focused on development, manufacturing and marketing of Active Pharmaceutical Ingredients (APIs), Intermediate Chemicals & Finished Dosages. Ever since its establishment in 1993, Hetero showed a tradition of excellence and deep sense of commitm

Lupin Limited is a global pharmaceutical leader headquartered in Mumbai, India, with products distributed in over 100 markets. Lupin specializes in pharmaceutical products, including branded and generic formulations, complex generics, biotechnology products, and active pharmaceutical ingredients. Tr

Cipla is a leading global pharmaceutical company trusted by healthcare professionals and patients across the world since 1935. A compassionate approach to healthcare that goes beyond the pursuit of profit and growth has been the force impelling Cipla’s history over the years. Our credo and our purp

Sun Pharma is the world's fourth-largest speciality generic pharmaceutical company and No. 1 in India. We provide high-quality, affordable medicines trusted by customers and patients in over 100 countries. Sun Pharma's global presence is supported by more than 40 manufacturing facilities spread acro

The Zydus Group with an overarching purpose of empowering people with freedom to live healthier and more fulfilled lives, is an innovative, global life-sciences company that discovers, develops, manufactures, and markets a broad range of healthcare therapies. The group employs over 27000 people worl

At Janssen, we never stop working toward a future where disease is a thing of the past. We’re the Pharmaceutical Companies of Johnson & Johnson, and you can count on us to keep working tirelessly to make that future a reality for patients everywhere, by fighting sickness with science, improving ac
EMS is the leading pharmaceutical company in Brazil. Established since 45 years and with 100% national capital, the company has two industrial plants strategically placed in São Bernardo do Campo and Hortolândia, in the state of São Paulo. With a work based on daring, simplicity, excellence and res
.png)
Community pharmacies are essential to health and wellness and have a huge impact on public health. They do much more than fill prescriptions...
In 2023, 725 data breaches were reported to OCR and across those breaches, more than 133 million records were exposed or impermissibly disclosed.
CVS Health is facing a probe into potential HIPAA violations related to the alleged use of patient data for lobbying purposes to prevent the...
CVS Health sued Arkansas, trying to thwart a law the healthcare company said would lead to the closure of all 23 CVS drugstores in the...
The pending sale of millions of customer health records as part of Rite Aid Corp. 's bankruptcy proceedings is putting a spotlight on data security protections.
The Pharmacy Technician Career Exploration Program provides students with hands-on training, professional mentorship, and externship opportunities.
CVS Health chief executive officer David Joyner named a new chief financial officer and chief medical officer as he fills out his new...
DALLAS (KTVT) - The family of a security guard fatally shot while confronting shoplifters at a CVS Pharmacy in Dallas is struggling with raw...
CVS Health has announced that all commercial prescriptions dispensed through its pharmacies will be now contracted through the company's CostVantage...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of CVS Pharmacy is https://cvs.co/linkedinprofiles.
According to Rankiteo, CVS Pharmacy’s AI-generated cybersecurity score is 737, reflecting their Moderate security posture.
According to Rankiteo, CVS Pharmacy currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, CVS Pharmacy is not certified under SOC 2 Type 1.
According to Rankiteo, CVS Pharmacy does not hold a SOC 2 Type 2 certification.
According to Rankiteo, CVS Pharmacy is not listed as GDPR compliant.
According to Rankiteo, CVS Pharmacy does not currently maintain PCI DSS compliance.
According to Rankiteo, CVS Pharmacy is not compliant with HIPAA regulations.
According to Rankiteo,CVS Pharmacy is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
CVS Pharmacy operates primarily in the Pharmaceutical Manufacturing industry.
CVS Pharmacy employs approximately 53,044 people worldwide.
CVS Pharmacy presently has no subsidiaries across any sectors.
CVS Pharmacy’s official LinkedIn profile has approximately 173,748 followers.
CVS Pharmacy is classified under the NAICS code 3254, which corresponds to Pharmaceutical and Medicine Manufacturing.
Yes, CVS Pharmacy has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/cvs-pharmacy.
Yes, CVS Pharmacy maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cvs-pharmacy.
As of December 11, 2025, Rankiteo reports that CVS Pharmacy has experienced 3 cybersecurity incidents.
CVS Pharmacy has an estimated 5,412 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with data breach notification letters sent to affected individuals, and communication strategy with public disclosure via california office of the attorney general..
Title: CVS Pharmacy Data Breach
Description: CVS Pharmacy, Inc. suffered a cybersecurity incident that compromised the personal information of more than 6,000 consumers. An unauthorized party breached the company’s network servers and gained access to certain individuals’ names, addresses, and protected health information. CVS sent out data breach notification letters to those whose information was impacted in the breach.
Type: Data Breach
Attack Vector: Unauthorized Access
Title: CVS Pharmacy Data Breach
Description: The California Office of the Attorney General reported that CVS Pharmacy, Inc. experienced a data breach involving unauthorized access to the CVSPhoto.com website between June 19, 2014, and July 14, 2015. The breach potentially affected customers' first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, and usernames and passwords, but not PIN numbers or photographic images. It is estimated that thousands of individuals' payment card information may have been compromised.
Date Detected: 2015-07-14
Type: Data Breach
Attack Vector: Unauthorized Access
Title: CVS Pharmacy Data Breach via Password Spraying Attack
Description: The California Office of the Attorney General reported a data breach involving CVS Pharmacy, discovered on January 6, 2022. The breach resulted from automated attempts to log in to customer accounts through password spraying, potentially compromising personal information such as customer names, dates of birth, mailing addresses, email addresses, and limited prescription information. The number of affected individuals is unknown.
Date Detected: 2022-01-06
Date Publicly Disclosed: 2022-02-11
Type: Data Breach
Attack Vector: Password Spraying
Vulnerability Exploited: Weak or Reused Credentials
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Customer Account Credentials (Password Spraying).

Data Compromised: Names, Addresses, Protected health information
Systems Affected: Network Servers

Data Compromised: First and last names, Payment card numbers, Expiration dates, Card verification codes, Addresses, Phone numbers, Email addresses, Usernames and passwords
Systems Affected: CVSPhoto.com website
Payment Information Risk: High

Data Compromised: Customer names, Dates of birth, Mailing addresses, Email addresses, Limited prescription information
Brand Reputation Impact: Potential Negative Impact (Undisclosed Severity)
Identity Theft Risk: High (Personal Information Exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Addresses, Protected Health Information, , First And Last Names, Payment Card Numbers, Expiration Dates, Card Verification Codes, Addresses, Phone Numbers, Email Addresses, Usernames And Passwords, , Personal Information, Prescription Information (Limited) and .

Entity Name: CVS Pharmacy, Inc.
Entity Type: Company
Industry: Healthcare
Customers Affected: 6,000

Entity Name: CVS Pharmacy, Inc.
Entity Type: Company
Industry: Pharmacy
Location: California
Customers Affected: Thousands

Entity Name: CVS Pharmacy
Entity Type: Corporation
Industry: Healthcare/Pharmacy
Location: United States (Primarily California)
Customers Affected: Unknown

Communication Strategy: Data breach notification letters sent to affected individuals

Communication Strategy: Public Disclosure via California Office of the Attorney General

Type of Data Compromised: Names, Addresses, Protected health information
Number of Records Exposed: 6,000

Type of Data Compromised: First and last names, Payment card numbers, Expiration dates, Card verification codes, Addresses, Phone numbers, Email addresses, Usernames and passwords
Number of Records Exposed: Thousands
Sensitivity of Data: High
Personally Identifiable Information: Yes

Type of Data Compromised: Personal information, Prescription information (limited)
Number of Records Exposed: Unknown
Sensitivity of Data: High (PII and Health-Related Data)
Data Exfiltration: Likely (Unauthorized Access Confirmed)

Regulations Violated: Potential HIPAA (Health Insurance Portability and Accountability Act) Violations, California Consumer Privacy Act (CCPA) Notification Requirements,
Regulatory Notifications: California Office of the Attorney General

Source: California Office of the Attorney General

Source: California Office of the Attorney General
Date Accessed: 2022-02-11
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General, and Source: California Office of the Attorney GeneralDate Accessed: 2022-02-11.

Investigation Status: Disclosed; Further Details Unclear
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data breach notification letters sent to affected individuals and Public Disclosure via California Office of the Attorney General.

Entry Point: Customer Account Credentials (Password Spraying)
High Value Targets: Customer Personal and Prescription Data
Data Sold on Dark Web: Customer Personal and Prescription Data

Root Causes: Weak Authentication Mechanisms (Susceptibility to Password Spraying)
Most Recent Incident Detected: The most recent incident detected was on 2015-07-14.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-02-11.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Addresses, Protected Health Information, , first and last names, payment card numbers, expiration dates, card verification codes, addresses, phone numbers, email addresses, usernames and passwords, , Customer Names, Dates of Birth, Mailing Addresses, Email Addresses, Limited Prescription Information and .
Most Significant System Affected: The most significant system affected in an incident was CVSPhoto.com website.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were addresses, Addresses, phone numbers, Limited Prescription Information, Email Addresses, expiration dates, usernames and passwords, Mailing Addresses, Dates of Birth, Protected Health Information, Names, first and last names, Customer Names, card verification codes, email addresses and payment card numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 6.0M.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Disclosed; Further Details Unclear.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Customer Account Credentials (Password Spraying).
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.