Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Clorox Sues Cognizant for $380 Million Over 2023 Hack

Clorox is blaming Congnizat for the 2023 cyberattack, claiming that the IT provided handed over passwords to the hackers.

Baig WhatsApp security lawsuit

Cleaning products giant Clorox has filed a lawsuit against IT services provider Cognizant, accusing the company of making it easy for hackers to breach its systems in the 2023 cyberattack.

Clorox is seeking $380 million from Cognizant, which includes $49 million in remedial costs — this amount was previously reported by Clorox — and hundreds of millions of dollars in losses caused by business interruption.

The cybersecurity incident came to light in August 2023, when Clorox reported shutting down some systems in response to a hacker attack. The company later said the damaging cyberattack caused significant disruptions to its operations, which led to product shortages

While it has not been confirmed, the attack was linked at the time to the notorious Scattered Spider cybercrime group, which has recently been once again highly active. Several alleged members of the gang have been arrested and prosecuted over the past year.  

In the complaint against Cognizant (courtesy of Dark Web Informer), Clorox said the company had provided support services, including for recovering and resetting passwords.

Clorox said Cognizant employees did not follow established procedures and failed to authenticate the individuals requesting password recovery or reset assistance. 

Advertisement. Scroll to continue reading.

The cleaning products firm has shared some of the conversations between the hackers and Cognizant staff, and they apparently show that the cybercriminals were indeed easily handed over the credentials they requested.

Clorox said Congizant employees — over several calls — reset passwords associated with Okta access, and helped the attackers reset multi-factor authentication (both Okta and Microsoft MFA), without verifying the alleged caller’s identity. 

“Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques. The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox’s network, and Cognizant handed the credentials right over,” Clorox alleges in the lawsuit.

While Clorox claims that Cognizant had been tasked with helping “guard the proverbial front door”, the IT services provider said in a statement to the media that it had not been in charge of Clorox’s cybersecurity.

“It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack,” Cognizant said. “Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed. Cognizant did not manage cybersecurity for Clorox.”

Related: Settlement Reached in Investors’ Lawsuit Against Meta CEO Mark Zuckerberg and Other Company Leaders

Related: Google Agrees to $1.3 Billion Settlement in Texas Privacy Lawsuits

Related: T-Mobile Coughed Up $33 Million in SIM Swap Lawsuit

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Neill Feather has been named Chief Executive Officer at Point Wild.

Oasis Security has appointed Michael DeCesare as President.

Sterling Wilson has joined IGEL as Global Field CTO, Business Continuity and Disaster Recovery.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.