The Financial Comet
  • Business
  • World News
  • Politics
  • Investing
  • Business
  • World News
  • Politics
  • Investing

The Financial Comet

Business

Lawsuit says Clorox hackers got passwords simply by asking

by admin July 24, 2025
July 24, 2025
Lawsuit says Clorox hackers got passwords simply by asking

WASHINGTON — Bleach maker Clorox said Tuesday that it has sued information technology provider Cognizant over a devastating 2023 cyberattack, alleging that the hackers pulled off the intrusion simply by asking the tech company’s staff for employees’ passwords.

Clorox was one of several major companies hit in August 2023 by the hacking group dubbed Scattered Spider, which specializes in tricking IT help desks into handing over credentials and then using that access to lock them up for ransom. The group is often described as unusually sophisticated and persistent, but in a case filed in California state court on Tuesday, Clorox said one of Scattered Spider’s hackers was able to repeatedly steal employees’ passwords simply by asking for them.

“Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques,” according to a copy of the lawsuit reviewed by Reuters. “The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox’s network, and Cognizant handed the credentials right over.”

Cognizant did not immediately return a message seeking comment on the suit, which was not immediately visible on the public docket of the Superior Court of Alameda County. Clorox provided Reuters with a receipt for the lawsuit from the court.

Three partial transcripts included in the lawsuit allegedly show conversations between the hacker and Cognizant support staff in which the intruder asks to have passwords reset and the support staff complies without verifying who they are talking to, for example by quizzing them on their employee identification number or their manager’s name.

“I don’t have a password, so I can’t connect,” the hacker says in one call. The agent replies, “Oh, ok. Ok. So let me provide the password to you ok?”

The 2023 hack caused $380 million in damages, Clorox said in the suit, about $50 million of which were tied to remedial costs and the rest of which were attributable to Clorox’s inability to ship products to retailers in the wake of the hack.

Clorox said the clean-up was hampered by other failures by Cognizant’s staff, including failure to de-activate certain accounts or properly restore data.

This post appeared first on NBC NEWS

previous post
China denies wrongdoing in preventing dozens of Americans from leaving under shadow ‘exit ban’
next post
Credit card startup Imprint beats big banks for Rakuten co-brand deal

Related Posts

Disney tops quarterly profit estimates but starts to...

February 6, 2025

With Trump all-in on crypto, bitcoin bulls bet...

February 14, 2025

Elon Musk confirms Tesla has signed a $16.5...

July 29, 2025

LimeWire acquires Fyre Festival, asking ‘What Could Possibly...

September 17, 2025

Applebee’s owner Dine Brands to lean on value,...

March 8, 2025

Amazon and Nvidia say AI data center demand...

April 25, 2025

Art created autonomously by AI can’t be copyrighted,...

March 21, 2025

Columbia Sportswear sues Columbia University, alleging trademark infringement

August 5, 2025

Tesla denies report it’s looking to replace Elon...

May 3, 2025

Home Depot is buying GMS for about $4.3...

July 1, 2025

    Join our mailing list to get access to special deals, promotions, and insider information. Your exclusive benefits await! Enjoy personalized recommendations, first dibs on sales, and members-only content that makes you feel like a true VIP. Sign up now and start saving!


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Editors’ Picks

    • 1

      DeepSeek hit with large-scale cyberattack, says it’s limiting registrations

      January 28, 2025
    • 2

      Trump re-designates Iranian-backed Houthis as terrorists: ‘Threaten[s] security of American civilians’

      January 23, 2025
    • 3

      Universal’s ‘Wicked: For Good’ creates a unique marketing challenge

      January 27, 2025
    • 4

      UnitedHealthcare taps company veteran Tim Noel as new CEO following Brian Thompson killing

      January 27, 2025
    • 5

      Bank of America CEO says financial industry will jump into crypto payments if regulators allow it

      January 23, 2025
    • 6

      FDA officially authorizes Zyn nicotine pouches for sale following health review

      January 23, 2025
    • 7

      Lara Trump to host weekend show on Fox News

      February 7, 2025
    • About us
    • Contacts
    • Privacy Policy
    • Terms and Conditions
    • Email Whitelisting

    Disclaimer: thefinancialcomet.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.


    Copyright © 2025 thefinancialcomet.com | All Rights Reserved