Summary
- Environment: CVS.com, CVSHealth.com, and the CVS mobile application
- Operational impact: No operational disruption is documented in the reviewed court records
- Financial impact: $20.5 million proposed maximum cash payment, including benefits, administration, fees, costs, and awards
- Record status: Developing record. Reviewed September 23, 2026; updated as evidence emerges.
What happened
The settlement agreement in Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp. says Criteo provided advertising support on the CVS website and mobile application. Plaintiffs alleged that technology embedded in CVS digital properties disclosed user data to Criteo or other technology providers. [1]
CVS and Criteo deny wrongdoing. The preliminary approval order says the proposed settlement is not an admission of fault or liability and is not a finding that the claims or alleged violations are valid. [1][2]
Impact
- The released allegations cover health or private information, personal information, browsing data, identifiers, or other CVS digital-property user data. The court records do not establish a uniform field set or an affected-person count. [1][2]
- For settlement purposes, the class covers living individuals who accessed CVS digital properties in the United States before July 27, 2026, subject to stated exclusions and valid opt-outs. This class definition is not a count of people whose data was proven disclosed. [1][2]
- The agreement defines a $20.5 million maximum cash payment for class benefits, settlement administration, court-approved attorneys’ fees and costs, and service awards. It is not a final judgment or a confirmed incident-loss figure. [1]
- Class members could submit one valid claim per household for up to $5 without proof or up to $10 with reasonable proof of class membership, subject to possible proportional reductions. [1]
Timeline
Putative class complaint filed
The settlement agreement says the plaintiffs filed the putative class complaint on May 15, 2026.
[1]Settlement preliminarily approved
The court filed its preliminary approval order, allowing the settlement notice and claims process to proceed without deciding the merits.
[2]Briefing updated
This briefing was last reviewed and updated on September 23, 2026.
Threat Group & Attack Vector
The reviewed records describe an alleged disclosure through technology embedded on CVS digital properties. They do not identify the specific technology, a conventional system intrusion, malware, an exploited vulnerability, or an exact disclosure period. [1][2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The parties proposed a settlement instead of continuing the litigation, and the court preliminarily approved the agreement and notice program. The settlement remained subject to final approval at the research cutoff, and neither the agreement nor the preliminary order resolves whether the alleged disclosure occurred or whether either defendant violated the law. [1][2]
