CVS accidentally leaks a billion user site records

Best cloud databases
(Image credit: Pixabay)

Cybersecurity researchers have chanced upon an unsecured database of healthcare and retail giant CVS that could have been used to identify customers.

According to security expert Jeremiah Fowler, the database measured over 200GB and contained over a billion records. The database contained a large number of searches on CVS.com and CVSHealth.com for medications and Covid-19 vaccines, and other items.

Surprisingly though, the database marked as “production” also housed a large number of email addresses. 

“CVS Health acted fast and professionally to secure the data and a member of their Information Security Team contacted me the following day and confirmed my findings and that the data was indeed theirs,” Fowler noted.

CVS told Forbes that the database was looked after by a third-party vendor, and was quickly taken down after Fowler flagged the leak.

Incessant logging

Fowler noticed the email addresses from all the popular email service providers while perusing the database for personally identifiable information.

Mostly though, the database contained records that indicated visitors searching for a range of items.

During his communication with CVS, Fowler learnt that the database was a dump of the queries entered into the search bar. Since most of the email addresses were entered on mobile devices, he fathoms that the app’s user interface misled users into entering their email address in the search bar thinking they were logging into their account.

Fowler believes the inadvertent collection of email addresses, highlights the risks of incessant activity logging.

“I recommended to CVS that in the future they should block any searches that match email address patterns or domain names from being executed or logged. This could help avoid unwanted data from being collected or stored,” Fowler suggests.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
healthcare
Over a million clinical records exposed in data breach
Data leak
Top collectibles site leaks personal data of nearly a million users
Data Breach
Thousands of healthcare records exposed online, including private patient information
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
iPhone 13 mini
The iPhone mini won't be returning, according to rumors – and you think that's a mistake