Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Clorox Sues IT Provider Cognizant For Simply Giving Employee Password to Hackers

Posted on July 23, 2025July 23, 2025 By CWS

The Clorox Firm, a number one family items producer, has filed a $380 million lawsuit towards IT providers supplier Cognizant Know-how Options.

The lawsuit accuses Cognizant’s help-desk brokers of inadvertently offering hackers with entry to Clorox’s community throughout a safety breach in August 2023. This intrusion severely disrupted operations and led to months of product shortages.

The 87-page criticism, lodged Tuesday in Alameda County Superior Courtroom, alleges that Cognizant brokers repeatedly reset passwords and multi-factor authentication (MFA) tokens for callers who posed as Clorox workers with out asking a single safety query.

Partial name transcripts filed with the go well with present one agent volunteering, “Let me present the password to you,” after the hacker stated he couldn’t log in.

Clorox contends that misplaced belief allowed the Scattered Spider social-engineering group to paralyze manufacturing strains, drive handbook order processing, and incur roughly $49 million in remediation prices, in addition to a whole lot of thousands and thousands in misplaced gross sales.

Clorox says it had offered Cognizant with strict credential-reset protocols akin to verifying a supervisor’s identify and sending affirmation emails, however that the seller falsely assured the corporate its employees had been “educated” on the foundations months earlier than the breach.

“Cognizant was not duped by any elaborate ploy or refined hacking methods,” the criticism states. “The cybercriminal simply known as … and Cognizant handed the credentials proper over”.

Reads the criticism

Past the preliminary entry, Clorox accuses Cognizant of botching the emergency response.

In accordance with the submitting, the seller took greater than an hour to reinstall a safety instrument after the intruder disabled it, equipped an incorrect listing of managed IP addresses, and dispatched engineers who lacked primary information of Clorox’s setting, forcing the producer to rent one other agency.

Cognizant, which reported almost $20 billion in 2024 income and hailed its “momentum” in a February earnings launch, denies wrongdoing.

“Clorox employed Cognizant for a slender scope of help-desk providers, which Cognizant fairly carried out,” an organization spokesperson stated in an emailed assertion Wednesday. “We’ll vigorously defend towards these baseless allegations”.

Related help-desk exploits slammed on line casino operator MGM Resorts final 12 months and proceed to plague companies that depend on exterior assist desks.

The August 2023 incident stays one of many costliest supply-chain hacks in latest reminiscence. Clorox disclosed in SEC filings that disruptions shaved as much as 28 % off quarterly gross sales and value an extra $49 million in restoration bills.

Shares fell greater than 25 % within the weeks after the breach, erasing billions in market worth.

No listening to date has been set, however the case might considerably affect contracting requirements between Fortune 500 corporations and their IT outsourcing companions. “Boards are watching,” stated Gartner analyst Pranav Patel.

“If help-desk hygiene can value almost half a billion {dollars}, count on each SLA to embed stricter authentication necessities and heavy penalties after they aren’t adopted.”

For now, Clorox says it has rebuilt its networks and returned to automated order processing, whereas Cognizant faces intensified scrutiny over how a routine assist name spiraled right into a disaster with sweeping operational and authorized fallout.

Increase detection, scale back alert fatigue, speed up response; all with an interactive sandbox constructed for safety groups -> Strive ANY.RUN Now 

Cyber Security News Tags:Clorox, Cognizant, Employee, Giving, Hackers, Password, Provider, Simply, Sues

Post navigation

Previous Post: Organizations Warned of Interlock Ransomware Attacks
Next Post: Ransomware Gangs Leveraging RMM Tools to Attack Organizations and Exfiltrate Data

Related Posts

PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability Cyber Security News
Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild Cyber Security News
Securing Remote Endpoints in Distributed Enterprise Systems Cyber Security News
New Report Uncover That Chinese Hackers Attempted To Compromise SentinelOne’s Own Servers Cyber Security News
New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers Cyber Security News
Identity Theft Surges as Criminals Deploy Advanced Tactics to Steal Personal Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Key Administrator of World’s Most Popular Dark Web Cybercrime Platform Arrested
  • Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware
  • How Businesses Prevent Credential Theft with Early Phishing Detection
  • Silicon Valley Engineer Pleads Guilty to Stealing Missile Detection Data for China
  • Coyote Malware Abuses Microsoft’s UI Automation in Wild to Exfiltrate Login Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Key Administrator of World’s Most Popular Dark Web Cybercrime Platform Arrested
  • Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware
  • How Businesses Prevent Credential Theft with Early Phishing Detection
  • Silicon Valley Engineer Pleads Guilty to Stealing Missile Detection Data for China
  • Coyote Malware Abuses Microsoft’s UI Automation in Wild to Exfiltrate Login Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News