financetom
Business
financetom
/
Business
/
Clorox Claims Cognizant Handed Credentials To Hacker, Ignored Security Protocols (UPDATED)
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Clorox Claims Cognizant Handed Credentials To Hacker, Ignored Security Protocols (UPDATED)
Jul 31, 2025 4:18 PM

Editor’s Note: The story has been updated with statement from Cognizant

Clorox Company ( CLX ) has accused IT services provider Cognizant Technology Solutions Corp ( CTSH ) of gross negligence and breach of trust after a cyberattack caused widespread disruption and nearly $380 million in damages.

According to Clorox, the root cause of the attack was Cognizant's failure to follow basic cybersecurity protocols it had agreed to uphold under a long-standing partnership.

For more than a decade, Clorox relied on Cognizant to operate its employee service desk, including tasks such as password recovery and credential resets.

Also Read: Clorox Stock Drops After Worse-Than-Expected Q3 Results: ‘Heightened Macroeconomic Uncertainties’ Lowered Sales, CEO says

The responsibility came with a clear requirement: no credentials would be reset without properly authenticating the requester. Despite repeated assurances, Cognizant allegedly failed to follow these procedures.

In an emailed statement to Benzinga, Cognizant spokesperson said, “It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack. Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed.  Cognizant did not manage cybersecurity for Clorox.“

On Aug. 11, 2023, a cybercriminal contacted the Cognizant-run service desk and was given direct access to Clorox's network credentials without facing any authentication checks.

This lapse happened multiple times that day, giving the attacker unfettered access to the company's systems. Clorox says audio recordings show Cognizant handing over credentials with no verification.

Cybercriminal: I don't have a password, so I can't connect.

Cognizant Agent: Oh, ok. Ok. So let me provide the password to you ok?

Cybercriminal: Alright. Yep. Yeah, what's the password?

Cognizant Agent: Just a minute. So it starts with the word "Welcome…

The cyberattack that followed crippled Clorox's corporate network, disrupted its supply chain, and significantly impaired its ability to fulfill orders.

According to the lawsuit filed by Clorox, Cognizant's mishandling of the initial credential requests was compounded by a botched incident response and disaster recovery effort, further worsening the damage.

Clorox maintains that Cognizant ignored the company's clearly outlined security procedures, which were designed to prevent exactly such an attack.

Despite touting its cybersecurity expertise and claiming to have trained its service desk staff in these protocols, Cognizant's actions—or inactions—revealed what Clorox called a "devastating lie."

The company says the breach could have been entirely avoided with proper training and adherence to security protocols.

Instead, Clorox was left dealing with over $49 million in direct recovery costs and hundreds of millions more in business interruption losses.

Meanwhile, Cognizant reported $20 billion in revenue in 2024, with no apparent hit to its brand or bottom line.

CTSH Price Action: Cognizant Tech Solns shares were up 0.72% at $77.34 on Wednesday, according to Benzinga Pro. The stock is trading within its 52-week range of $65.52 to $90.82.

Read Next:

Lockheed Martin Confirms Talks With US Over Trump’s $175 Billion ‘Golden Dome’ Missile Shield — CEO James Taiclet Says No Contracts Yet, LMT Is ‘All In’

Image via Mdisk/Shutterstock

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Medical device firm Zynex's Q3 revenue misses expectations
Medical device firm Zynex's Q3 revenue misses expectations
Nov 17, 2025
Overview * Zynex ( ZYXI ) Q3 revenue fell 73% yr/yr, missing analyst expectations * Company reported a Q3 net loss of $42.9 mln, impacted by asset impairment charges Outlook * Zynex ( ZYXI ) exploring strategic alternatives, including capital raising and restructuring * Company enters 30-day grace period for $1.5 mln interest payment Result Drivers * TRICARE PAYMENT SUSPENSION...
Elon Musk expected to attend Trump dinner with Saudi Crown Prince, Punchbowl reports
Elon Musk expected to attend Trump dinner with Saudi Crown Prince, Punchbowl reports
Nov 17, 2025
Nov 17 (Reuters) - Tesla CEO Elon Musk is expected to attend a Tuesday dinner that U.S. President Donald Trump is holding in honor of Saudi Crown Prince Mohammed bin Salman, Punchbowl News reported on Monday. ...
Fibre cement maker James Hardie reports 2% drop in second-quarter profit
Fibre cement maker James Hardie reports 2% drop in second-quarter profit
Nov 17, 2025
Nov 18 (Reuters) - Fibre cement maker James Hardie reported a 2% drop in its second-quarter profit on Tuesday, as weak single-family construction and ongoing inventory reductions in North America deepened demand pressures in a tough macroeconomic backdrop. The company also said it has appointed Ryan Lada as the new chief financial officer, succeeding Rachel Wilson effective immediately, and named...
Rio Tinto Plans to Cut Yarwun Alumina Output by 40%
Rio Tinto Plans to Cut Yarwun Alumina Output by 40%
Nov 17, 2025
05:30 PM EST, 11/17/2025 (MT Newswires) -- Rio Tinto (RIO) said Monday it will reduce production at its Yarwun alumina refinery in Gladstone by 40% starting in October 2026 to extend the operation's life to 2035. The tailings facility is expected to hit capacity in 2031, and the cut will trim annual output by about 1.2 million tonnes and impact...
Copyright 2023-2026 - www.financetom.com All Rights Reserved