CVS accidentally leaks a billion user site records Best cloud databases


Cybersecurity researchers have chanced upon an unsecured database of healthcare and retail giant CVS that could have been used to identify customers.
According to security expert Jeremiah Fowler, the database measured over 200GB and contained over a billion records. The database contained a large number of searches on CVS.com and CVSHealth.com for medications and Covid-19 vaccines, and other items.
Surprisingly though, the database marked as “production” also housed a large number of email addresses.
“CVS Health acted fast and professionally to secure the data and a member of their Information Security Team contacted me the following day and confirmed my findings and that the data was indeed theirs,” Fowler noted.
CVS told Forbes that the database was looked after by a third-party vendor, and was quickly taken down after Fowler flagged the leak.
Incessant logging
Fowler noticed the email addresses from all the popular email service providers while perusing the database for personally identifiable information.
Mostly though, the database contained records that indicated visitors searching for a range of items.
During his communication with CVS, Fowler learnt that the database was a dump of the queries entered into the search bar. Since most of the email addresses were entered on mobile devices, he fathoms that the app’s user interface misled users into entering their email address in the search bar thinking they were logging into their account.
Fowler believes the inadvertent collection of email addresses, highlights the risks of incessant activity logging.
“I recommended to CVS that in the future they should block any searches that match email address patterns or domain names from being executed or logged. This could help avoid unwanted data from being collected or stored,” Fowler suggests.
Cybersecurity researchers have chanced upon an unsecured database of healthcare and retail giant CVS that could have been used to identify customers. According to security expert Jeremiah Fowler, the database measured over 200GB and contained over a billion records. The database contained a large number of searches on CVS.com and…
Recent Posts
- Gabby Petito murder documentary sparks viewer backlash after it uses fake AI voiceover
- The quirky Alarmo clock is no longer exclusive to Nintendo’s online store
- The government is still threatening to ‘semi-fire’ workers who don’t answer an email from Elon Musk
- Sigma’s latest camera is so minimalist it doesn’t have a memory card slot
- Freedom of speech is ‘on the line’ in a pivotal Dakota Access Pipeline trial
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010