Clorox sues Cognizant for “giving away” passwords which led to major breach
- Clorox 2023 breach happened when a threat actor impersonated an employee and had their credentials reset
- Clorox argues Cognizant did not follow standard procedures
- Cognizant says cybersecurity wasn’t its job to begin with
Clorox is suing its IT service provider Cognizant following a 2023 ransomware attack which cost the firm millions of dollars in damages.
Recently filed with the Superior Court of California, the lawsuit says Cognizant is being sued for breach of contract, breach of the covenant of good faith and fair dealing, gross negligence, and intentional misrepresentation.
Back in 2013, Cognizant was contracted to operate Clorox’s employee service desk, which included tasks such as password recovery, credential resets, and IT support for staffers. In 2023, a cybercriminal called a Cognizant employee on the phone, said they were a Clorox employee, and asked for a password and multi-factor authentication (MFA) recovery, since they lost access to their account.
Whose job is it, anyway?
In the filing, Clorox argues the Cognizant employee complied without following established procedures on identity verification, providing alleged transcripts of phone calls between the attacker and the Cognizant employee which allegedly prove the password reset was granted on the spot.
Once the attackers gained access, they reset MFA tokens, changed phone numbers linked to SMS authentication, disabled cybersecurity tools, and exfiltrated sensitive files from the system.
As a result, Clorox had to shut down its systems, pause manufacturing, and rely on manual order processing for weeks. This allegedly resulted in hundreds of millions of dollars in lost sales and reputational damage.
Clorox is now seeking $49 million in direct remediation damages, as well as $380 million in total damages.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In response to the lawsuit, Cognizant told the press it wasn’t their job to defend the IT network from attacks.
Speaking to BleepingComputer, a company spokesperson said: “It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack. Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed. Cognizant did not manage cybersecurity for Clorox.”
You might also like
Clorox 2023 breach happened when a threat actor impersonated an employee and had their credentials reset Clorox argues Cognizant did not follow standard procedures Cognizant says cybersecurity wasn’t its job to begin with Clorox is suing its IT service provider Cognizant following a 2023 ransomware attack which cost the firm…
Recent Posts
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023