After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords
ID: 336dd004-aa02-5d78-abc7-c1bf91c22626
STIX ID: report--336dd004-aa02-5d78-abc7-c1bf91c22626
Feed Name: Ars Technica Security
Threat Score
According to the report, attackers successfully social-engineered Cognizant’s outsourced service desk to perform password and MFA resets for Clorox employees without proper identity verification, enabling intruders to access Clorox’s network, plant ransomware and exfiltrate data, and causing an estimated $380 million in damage; Clorox has sued Cognizant for failing to follow basic procedures and adequately train staff.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
