---
title: "CVS-Criteo alleged data disclosure"
description: "Court-sourced account of the CVS-Criteo digital privacy settlement, its disputed data-disclosure allegations, class scope, and proposed $20.5 million maximum payment."
incident_type: "Cybersecurity incident"
status: "active"
last_modified: "2026-09-23"
canonical_url: "https://www.ally.security/incidents/cvs-criteo-alleged-data-disclosure-2026"
markdown_url: "https://www.ally.security/incidents/cvs-criteo-alleged-data-disclosure-2026.md"
stix_url: "https://www.ally.security/incidents/cvs-criteo-alleged-data-disclosure-2026/stix.json"
---

# CVS-Criteo alleged data disclosure

A proposed settlement addresses disputed allegations that embedded technology disclosed CVS digital-property user data to Criteo or other providers.

Last modified Sep 23, 2026 · 2 sources

## Summary

- **Environment:** CVS.com, CVSHealth.com, and the CVS mobile application
- **Operational impact:** No operational disruption is documented in the reviewed court records
- **Financial impact:** $20.5 million proposed maximum cash payment, including benefits, administration, fees, costs, and awards

## What happened

The [settlement agreement](https://cw.simpluris.com/docs/public/downloads/CBC4/SETTLEMENT_AGREEMENT) in *Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.* says [Criteo](https://www.criteo.com/) provided advertising support on the [CVS](https://www.cvs.com/) website and mobile application. Plaintiffs alleged that technology embedded in CVS digital properties disclosed user data to Criteo or other technology providers. [1](#source-1)

CVS and Criteo deny wrongdoing. The [preliminary approval order](https://cw.simpluris.com/docs/public/downloads/CBC4/PRELIMINARY_APPROVAL_ORDER) says the proposed settlement is not an admission of fault or liability and is not a finding that the claims or alleged violations are valid. [1](#source-1) [2](#source-2)

## Impact

- The released allegations cover health or private information, personal information, browsing data, identifiers, or other CVS digital-property user data. The court records do not establish a uniform field set or an affected-person count. [1](#source-1) [2](#source-2)
- For settlement purposes, the class covers living individuals who accessed CVS digital properties in the United States before July 27, 2026, subject to stated exclusions and valid opt-outs. This class definition is not a count of people whose data was proven disclosed. [1](#source-1) [2](#source-2)
- The agreement defines a $20.5 million maximum cash payment for class benefits, settlement administration, court-approved attorneys' fees and costs, and service awards. It is not a final judgment or a confirmed incident-loss figure. [1](#source-1)
- Class members could submit one valid claim per household for up to $5 without proof or up to $10 with reasonable proof of class membership, subject to possible proportional reductions. [1](#source-1)

## Timeline

### May 15, 2026 — Putative class complaint filed

The [settlement agreement](https://cw.simpluris.com/docs/public/downloads/CBC4/SETTLEMENT_AGREEMENT) says the plaintiffs filed the putative class complaint on May 15, 2026. [1](#source-1)

### July 27, 2026 — Settlement preliminarily approved

The court filed its [preliminary approval order](https://cw.simpluris.com/docs/public/downloads/CBC4/PRELIMINARY_APPROVAL_ORDER), allowing the settlement notice and claims process to proceed without deciding the merits. [2](#source-2)

### September 23, 2026 — Briefing updated

This briefing was last reviewed and updated on September 23, 2026.

## Threat Group & Attack Vector

The reviewed records describe an alleged disclosure through technology embedded on CVS digital properties. They do not identify the specific technology, a conventional system intrusion, malware, an exploited vulnerability, or an exact disclosure period. [1](#source-1) [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The parties proposed a settlement instead of continuing the litigation, and the court preliminarily approved the agreement and notice program. The settlement remained subject to final approval at the research cutoff, and neither the agreement nor the preliminary order resolves whether the alleged disclosure occurred or whether either defendant violated the law. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/cvs-criteo-alleged-data-disclosure-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Settlement Agreement in Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.

legal · Parties to Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.

<https://cw.simpluris.com/docs/public/downloads/CBC4/SETTLEMENT_AGREEMENT>

<a id="source-2"></a>

### Order Granting Motion for Preliminary Approval

legal · Circuit Court of the 17th Judicial Circuit in and for Broward County, Florida · Jul 27, 2026

<https://cw.simpluris.com/docs/public/downloads/CBC4/PRELIMINARY_APPROVAL_ORDER>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: Class members could submit one valid claim per household for up to $5 without proof or up to $10 with reasonable proof of class membership, subject to possible proportional reductions.
2. **Resulted In · 100% confidence · current**  
   CVS digital-properties alleged data disclosure: Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.
3. **Resulted In · 90% confidence · disputed**  
   CVS digital-properties alleged data disclosure: Alleged CVS digital-property user-data disclosure
4. **Vendor Of · 100% confidence · current**  
   Criteo Corp.: CVS Pharmacy, Inc.
5. **Occurred At · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: 2026-05-15
6. **Resulted In · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: The court preliminarily approved the proposed settlement and notice program but said the order was not an admission of fault or liability or a finding that the claims or alleged violations were valid.
7. **Resulted In · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: 20,500,000 USD
8. **Resulted In · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: Preliminary settlement approval
9. **Occurred At · 100% confidence · current**  
   Preliminary settlement approval: 2026-07-27
10. **Affected Organization · 100% confidence · current**  
   CVS digital-properties alleged data disclosure: CVS Pharmacy, Inc.
11. **Resulted In · 90% confidence · disputed**  
   Alleged CVS digital-property user-data disclosure: Plaintiffs alleged disclosure of health or private information, personal information, browsing data, identifiers, or other CVS Digital Properties user data to Criteo or other technology providers through embedded technology.
12. **Resulted In · 100% confidence · current**  
   Brewer et al. v. CVS Pharmacy, Inc. and Criteo Corp.: For settlement purposes, the class covers living individuals who accessed CVS Digital Properties in the United States before July 27, 2026, subject to stated exclusions and valid opt-outs.

</details>
