financetom
Business
financetom
/
Business
/
Lawsuit says Clorox hackers got passwords simply by asking
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Lawsuit says Clorox hackers got passwords simply by asking
Jul 22, 2025 12:48 PM

WASHINGTON (Reuters) -Bleach maker Clorox said Tuesday that it has sued information technology provider Cognizant over a devastating 2023 cyberattack, alleging that the hackers pulled off the intrusion simply by asking the tech company's staff for employees' passwords.

Clorox was one of several major companies hit in August 2023 by the hacking group dubbed Scattered Spider, which specializes in tricking IT help desks into handing over credentials and then using that access to lock them up for ransom. The group is often described as unusually sophisticated and persistent, but in a case filed in California state court on Tuesday, Clorox said one of Scattered Spider's hackers was able to repeatedly steal employees' passwords simply by asking for them.

"Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques," according to a copy of the lawsuit reviewed by Reuters. "The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox's network, and Cognizant handed the credentials right over."

Cognizant did not immediately return a message seeking comment on the suit, which was not immediately visible on the public docket of the Superior Court of Alameda County. Clorox provided Reuters with a receipt for the lawsuit from the court.

Three partial transcripts included in the lawsuit allegedly show conversations between the hacker and Cognizant support staff in which the intruder asks to have passwords reset and the support staff complies without verifying who they are talking to, for example by quizzing them on their employee identification number or their manager's name.

"I don't have a password, so I can't connect," the hacker says in one call. The agent replies, "Oh, ok. Ok. So let me provide the password to you ok?"

The 2023 hack caused $380 million in damages, Clorox said in the suit, about $50 million of which were tied to remedial costs and the rest of which were attributable to Clorox's inability to ship products to retailers in the wake of the hack.

Clorox said the clean-up was hampered by other failures by Cognizant's staff, including failure to de-activate certain accounts or properly restore data.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Mental health network misled policyholders about provider options, lawsuit claims  
Mental health network misled policyholders about provider options, lawsuit claims  
May 25, 2025
April 28 (Reuters) - A mental health care provider network that works with the health insurance plan for New York State employees was hit with a federal lawsuit on Monday over claims it misled patients looking for in-network care with lists of providers who didn't exist, didn't accept the insurance or were otherwise unreachable. The proposed class action, filed in...
Brixmor Property Group Q1 FFO, Revenue Rise
Brixmor Property Group Q1 FFO, Revenue Rise
May 25, 2025
04:20 PM EDT, 04/28/2025 (MT Newswires) -- Brixmor Property Group ( BRX ) late Monday reported Q1 funds from operations of $0.56 per diluted share, compared with $0.54 a year earlier. Analysts polled by FactSet expected $0.55. Revenue for the quarter ended March 31 was $337.5 million, up from $320.2 million a year earlier. Analysts surveyed by FactSet expected $331.2...
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Aug 17, 2025
SYDNEY, Aug 18 (Reuters) - Google agreed on Monday to pay a A$55 million ($35.8 million) fine in Australia after the consumer watchdog found it had hurt competition by paying the country's two largest telcos to pre-install its search application on Android phones, excluding rival search engines. The fine extends a bumpy period for the Alphabet-owned internet giant in Australia,...
What's Going On With Advanced Micro Devices Stock Monday?
What's Going On With Advanced Micro Devices Stock Monday?
May 25, 2025
Advanced Micro Devices, Inc. ( AMD ) shares traded lower Monday. AMD, along with the semiconductor industry, may have reacted to reports suggesting Huawei developed an artificial intelligence (AI) chip to challenge NVIDIA Corp ( NVDA ) . What To Know: According to the Wall Street Journal, the Chinese technology company developed the Ascend 910D and began approaching other technology...
Copyright 2023-2026 - www.financetom.com All Rights Reserved