The CVS Corp. has cut off Web access to ExtraCare card holders’ detailed purchase information after a consumer group showed reporters how easily an intruder could log into the system and find out, say, how many condoms or enema kits someone’s bought.
CVS has issued about 50 million of the loyalty cards, which allow the drugstore chain to track each customer’s purchases and, in exchange, provide a 2-percent rebate on those purchases, along with customized coupons.
Seifert Systems Invests in Energy Efficiency to Strengthen Operations
For manufacturers, energy is more than just another operating expense. It plays a critical role…
Learn More
To log into your account on CVS.com, all you need is the card number, your ZIP code, and the first three letters of your surname. Even now, anyone with that information can easily find out the card holder’s home address, phone number, and total purchases each quarter.
But until last week, the Web site also allowed customers to request a detailed purchase report to be emailed to them – to any address they put in.
Then on Monday, Katherine Albrecht, founder and director of CASPIAN (Consumers Against Supermarket Privacy Invasion and Numbering), a grassroots group that opposes retailers’ use of cards like CVS’s ExtraCare, publicly exposed the security hole.
Albrecht had asked volunteers to sign up for a CVS ExtraCare card and purchase health-related items, then accessed their accounts with their card numbers and ZIP codes and and requested that purchase reports be sent to an email account she had set up.
In each case, CVS responded within 24 hours, sending her lists detailing purchases of such sensitive items as Trojan Twisted Pleasure condoms, a home pregnancy test kit, and enema kits, Albrecht said. A sample email is posted on CASPIAN’s home page, nocards.org.
The group said CVS was offering the email purchase histories so consumers could document their expenditures to be reimbursed through a flexible spending account, or FSA. ExtraCare is also a way to justify the company’s “enormous databases,” the group said.
“But the scheme backfired and has given us all a sense of how insecure the data really is,” Albrecht said. “This demonstration underscores why companies should not be collecting purchase information like this in the first place.”
The day after the CASPIAN exposé, CVS shut off that feature on its Web site, saying it would restore it only after tightening up security. Access to other ExtraCare account information, however, remained unchanged as of Wednesday.
CVS spokesman Todd Andrews told the Associated Press that the company had no knowledge of anyone gaining access to customer information improperly.
The Stop & Shop supermarket chain, which also has loyalty cards, does not allow consumers to access their purchase history online. To log in to make an account change, which the chain’s Web site does allow, customers need to type in, at a minimum, their card number, full name and address.











