logo

After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords

ID: 336dd004-aa02-5d78-abc7-c1bf91c22626

STIX ID: report--336dd004-aa02-5d78-abc7-c1bf91c22626

Feed Name: Ars Technica Security

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-04-19

Author: Nate Anderson

...
...

According to the report, attackers successfully social-engineered Cognizant’s outsourced service desk to perform password and MFA resets for Clorox employees without proper identity verification, enabling intruders to access Clorox’s network, plant ransomware and exfiltrate data, and causing an estimated $380 million in damage; Clorox has sued Cognizant for failing to follow basic procedures and adequately train staff.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.