CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
Social Engineering Examples·10 sources
Beginning around July 2006 and continuing into 2007, television and print media across the United States (most notably an Indianapolis WTHR/13 Investigates series by reporter Bob Segall, later expanded into a multi-city dumpster-diving investigation, with AP wire coverage) found that CVS pharmacy stores were discarding sensitive patient and employee records into open, publicly accessible dumpsters rather than shredding or securely destroying them.
Reporters recovered pill bottles bearing patient names, home addresses, prescribing physicians, medications and dosages; medication instruction sheets; pharmacy computer printouts; old prescriptions and refund records; credit card receipts; and employee employment applications and payroll records containing Social Security numbers. WTHR's investigation had itself been triggered by a real-world incident in Bloomington, Indiana: a man posing as a pharmacy employee tricked an elderly victim at her front door into handing over her OxyContin medication, after finding her prescription and address information in a CVS dumpster; this specific incident is documented in WTHR's own reporting (and AP wire syndication), not in the FTC complaint, which contains no named incident and only a general statement that dumpster-exposed data "can be obtained ... for purposes of identity theft or the theft of prescription medicines." The FTC and HHS Office for Civil Rights (OCR) opened coordinated investigations, and on February 18, 2009 announced a joint resolution: CVS Pharmacy, Inc. agreed to pay HHS OCR $2.25 million and adopt a three-year Corrective Action Plan to resolve potential HIPAA Privacy Rule violations (resolution agreement signed January 16, 2009), while CVS Caremark Corporation separately settled FTC charges of unfair and deceptive practices under Section 5 of the FTC Act via a consent order that became final on June 23, 2009. CVS admitted no liability in either settlement.
This was not a social-engineering attack on a person in the moment but a systemic physical-security failure that created raw material for social engineering and identity theft. CVS pharmacies' disposal practices left unsecured, unshredded documents containing protected health information (PHI) and personally identifiable information (PII) in dumpsters accessible to anyone.
The exposure method (dumpster diving) is a classic physical reconnaissance technique used to harvest data that then fuels impersonation and crime; this is illustrated by the Bloomington, Indiana case reported by WTHR and picked up by AP wire coverage, in which a thief used address and prescription information recovered from a CVS dumpster to pose as a pharmacy employee and trick an elderly victim into handing over her OxyContin medication at her front door.
That specific incident comes from WTHR's own investigative reporting (and subsequent AP syndication), not from the FTC complaint, which does not name any specific incident and only makes the general statement that dumpster-exposed data "can be obtained by individuals for purposes of identity theft or the theft of prescription medicines." The FTC's complaint framed CVS's conduct as an unfair practice because the resulting exposure was likely to cause substantial consumer injury that customers could not reasonably avoid, and it also alleged deceptive privacy claims; HHS framed it as a failure to implement HIPAA-required safeguards for disposal of PHI.
There was no lure directed at a targeted victim in the traditional social-engineering sense; the "lure" was structural negligence (documents in open trash) rather than a crafted pretext at the corporate level. The downstream crime enabled by that negligence used a classic pretext: per WTHR/AP reporting, a thief impersonated a pharmacy employee at an elderly victim's front door, using her real name, address, and prescription details (recovered from a CVS dumpster) to make the impersonation credible enough to convince her to hand over her OxyContin medication directly to him; no pharmacy refill or fraudulent transaction was involved.
CVS Pharmacy, Inc. paid $2,250,000 to HHS OCR and implemented a mandated 3-year Corrective Action Plan (revised policies, workforce training, internal monitoring, and reporting on disposal of PHI). CVS Caremark Corporation's FTC consent order required establishment of a comprehensive information security program, biennial independent third-party assessments for 20 years, and detailed recordkeeping, with no upfront monetary penalty but exposure to civil penalties for future violations of the order.
CVS publicly apologized, acknowledged the findings were unacceptable, and said it would require pharmacy waste to be bagged and returned to CVS warehouses rather than placed in store dumpsters, alongside revised in-store training. This was one of the earliest joint HHS-FTC enforcement actions combining HIPAA Privacy Rule and FTC Act authority over the same underlying conduct, and it functioned as a precursor to the subsequent, similarly structured Rite Aid dumpster-disposal case.
The case established that improper physical disposal of PHI/PII is independently enforceable both as a HIPAA violation and as an FTC-Act unfair/deceptive practice, and it shows how a purely physical-security lapse (unsecured trash) becomes an enabler for later social-engineering crime (impersonating a pharmacy employee using data scavenged from the trash).
It is frequently cited as a foundational case for "privacy by disposal" obligations in healthcare and retail, and as the model the FTC and HHS followed shortly after in the parallel Rite Aid dumpster-disposal enforcement action.
Shred or otherwise render unreadable any documents containing PHI/PII (prescription labels, pill bottles, medication records, employment/payroll records with SSNs, financial account data) before disposal; use locked/secured waste receptacles rather than open store dumpsters for pharmacy and HR waste; enforce documented, audited disposal procedures with employee training and periodic compliance checks; treat physical trash as an attack surface equivalent to digital systems for social-engineering risk, since scavenged personal details can be used to construct credible impersonation pretexts (e.g., posing as an employee) in follow-on crimes.
Social Engineering Examples. “CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)”. Accessed 19 September 2026. https://socialengineeringexamples.com/cvs-caremark-pharmacy-trash-disposal-2009
Opportunistic thieves and, per WTHR/AP reporting, at least one documented offender identify pharmacy locations that leave waste in open, publicly accessible dumpsters rather than locked or secured receptacles, typically through casual observation of a store's trash-handling habits rather than any digital reconnaissance.
Locking or securing store dumpsters, and using windowless, gated, or company-controlled enclosures instead of open public receptacles, removes the reconnaissance opportunity at its source; this is essentially the fix CVS adopted afterward.
The thief physically searches the unsecured dumpster and recovers discarded pharmacy and HR waste, pill bottles and prescription labels, patient information sheets, refill and computer printouts, credit card and insurance receipts, and employee applications or payroll records with Social Security numbers, the exact categories documented in the FTC complaint and WTHR's reporting.
Even where a dumpster is later reached, shredding or otherwise rendering PHI and PII unreadable before disposal (pill labels, prescription printouts, SSN-bearing HR records) means there is nothing usable to retrieve regardless of physical access.
The thief sorts recovered material into what is directly usable for financial/identity fraud (SSNs, card and insurance numbers) versus what can support a credible impersonation of pharmacy staff (a real patient's name, address, medication, dosage, and prescribing physician), consistent with how WTHR described the Bloomington, Indiana case unfolding.
The same destroy-before-disposal control removes the raw material for triage; there is no separate practical defense once intact records are already in an attacker's hands, so this stage is best addressed by preventing Stage 2's collection rather than intercepting sorting after the fact.
Using the victim's own real prescription details recovered from the trash, the thief builds a pretext of being a pharmacy employee or technician who needs to correct a filling error, a story that only works because it is grounded in accurate, victim-specific data the thief should not otherwise have.
Pretext construction happens off-site with no visibility to the pharmacy or the eventual victim, so it cannot be directly detected or blocked; the realistic control is upstream (destroying the data that makes the pretext credible, per Stage 2) rather than trying to catch the pretext being built.
Per WTHR and AP wire reporting, the thief approached the elderly victim at her front door posing as pharmacy staff, invoking the fabricated "filling error" and urgency to persuade her to hand over her prescription medication directly, with no digital system or transaction involved.
Consumer and employee education that legitimate pharmacy staff do not make unannounced home visits to reclaim or correct dispensed medication, paired with a standing instruction to verify any such claim by calling the pharmacy's published number before handing anything over, would have interrupted the in-person impersonation.
For the Bloomington incident, the thief left with the victim's OxyContin in hand, a high-value controlled substance obtainable without ever needing to defraud CVS's own systems; separately, the SSNs, payment-card, and insurance data exposed by the same disposal failure created an ongoing, harder-to-quantify risk of identity theft and financial fraud against other customers and employees, which is the harm the FTC and HHS complaints centered on even though no other individual case was named in the settlements.
Once medication has been physically handed over there is no technical recovery, making Stage 5's verification habit the last real intervention point for that specific harm; for the broader identity-theft and financial-fraud risk from exposed SSNs and card data, standard post-exposure controls (credit freezes, fraud alerts, breach monitoring) reduce downstream damage but do not prevent it, which is why regulators required CVS to fix disposal practices (Stage 2) rather than relying on after-the-fact monitoring alone.
Browse by what this case has in common with others in the library.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to…
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake…
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.