Supply chain
β Supply Chain
CVS Health Third-Party Breach (June 2021)
Primary Source βIncident Details
CVS Health Faces Data Breach,1B Search Records Exposed | TechTarget. A CVS Health data breach led to over 1 billion search records being accidentally posted online, as reported by an independent cybersecurity researcher. More than 1 billion CVS Health search records were accidentally posted online in a data breach incident in late March by an unnamed third party vendor. Independent cybersecurity researcher Jerimiah Fowler discovered the breach and quickly alerted CVS and the database was taken offline on the same day. The records contained search data from CVS.com and CVSHealth.com for both COVID-19 vaccines and medications. In most cases, the search data could not be linked to a specific person, Fowler told Forbes.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2021-06-01 Breach occurred
- 2021-06-21 Publicly disclosed