Nbcchicago CVS Settles Class Action for $20.5 Million Over Data Privacy Violations
Article Content
- •CVS faces a $20.5 million settlement for data privacy violations.
- •Affected users can claim up to $10 with proof of use.
- •Claims must be submitted by November 16, 2026.
CVS has agreed to a $20.5 million settlement due to allegations of improperly disclosing user data from its website and app to third parties, including Criteo. The settlement affects U.S. residents who accessed CVS digital properties before July 27, 2026. Eligible claimants can receive up to $10 with documentation or $5 without. CVS denies wrongdoing but opted to settle to avoid prolonged litigation. Claims must be filed by November 16, 2026, with a final approval hearing scheduled for December 1, 2026. Payments will be distributed 120 days post-approval, barring any appeals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…