US bleach co Clorox sues Cognizant over cyberattack
BENGALURU: US household goods manufacturer Clorox sued Cognizant for $380 million, alleging that the latter's service desk granted access to cybercriminals to Clorox's network by providing login credentials without properly verifying the requester's identity or following Clorox's authentication processes.
"The resulting cyberattack was debilitating. It paralysed Clorox's corporate network and crippled business operations. And to make matters worse, when Clorox called on Cognizant to provide incident response and disaster recovery support services, Cognizant botched its response and compounded the damage it already caused," Clorox said in its complaint.
The complaint alleged that the cyberattack caused Clorox approximately $380 million in damages, including over $49 million in remedial costs alone to fix the damage caused by Cognizant's entirely preventable errors, and hundreds of millions of dollars in business interruption losses because the cyberattack impeded Clorox's ability to ship orders and keep its products on the shelves of retailers.
Clorox entered into an agreement with Cognizant in 2013 that included service desk support and identity management. The complaint said that Cognizant operated the service desk for Clorox and provided IT support for Clorox employees, including employee credential recovery when needed.
The cybercriminal called the Cognizant service desk a second time, again masquerading as Clorox employee 1, it said. On August 11, 2023, the cybercriminal initially contacted the service desk to request a reset of employee 1's password for Okta, an identity management tool Clorox used to verify network access. The agent replied by asking the cybercriminal to connect to Clorox's virtual private network (VPN). The cybercriminal then claimed he could not access the VPN without a password. The complaint said without any additional questions or identity checks, the agent reset Clorox's password, directly violating Clorox's credential support protocols.
When TOI reached out to Cognizant, its spokesperson said, "It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack. Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed. Cognizant did not manage cybersecurity for Clorox."
Stay informed with the latest business news, updates on bank holidays and public holidays.
AI Masterclass for Students. Upskill Young Ones Today!– Join Now
The complaint alleged that the cyberattack caused Clorox approximately $380 million in damages, including over $49 million in remedial costs alone to fix the damage caused by Cognizant's entirely preventable errors, and hundreds of millions of dollars in business interruption losses because the cyberattack impeded Clorox's ability to ship orders and keep its products on the shelves of retailers.
Clorox entered into an agreement with Cognizant in 2013 that included service desk support and identity management. The complaint said that Cognizant operated the service desk for Clorox and provided IT support for Clorox employees, including employee credential recovery when needed.
The cybercriminal called the Cognizant service desk a second time, again masquerading as Clorox employee 1, it said. On August 11, 2023, the cybercriminal initially contacted the service desk to request a reset of employee 1's password for Okta, an identity management tool Clorox used to verify network access. The agent replied by asking the cybercriminal to connect to Clorox's virtual private network (VPN). The cybercriminal then claimed he could not access the VPN without a password. The complaint said without any additional questions or identity checks, the agent reset Clorox's password, directly violating Clorox's credential support protocols.
When TOI reached out to Cognizant, its spokesperson said, "It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack. Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed. Cognizant did not manage cybersecurity for Clorox."
Stay informed with the latest business news, updates on bank holidays and public holidays.
AI Masterclass for Students. Upskill Young Ones Today!– Join Now
Popular from Business
- Grief, boardroom and the game of succession: Inside family feud tearing through Sona Comstar after Sunjay Kapur’s death
- EU sanctions on Russia oil: Indian oil refiner Nayara Energy CEO Alessandro des Dorides resigns; Russia-backed refinery key fuel retailer
- Empowering retail investors in India’s F&O market: A graphic-first approach to intuitive investing
- In just 5 years, Tata Group's semiconductor business becomes a major revenue source
- ‘Confident India will get special treatment…’: Piyush Goyal says trade deal talks with US making ‘fantastic’ progress; ‘important to…’
end of article
Trending Stories
- Ciara and baby Amora twin in new adorable photo as fans gush over Russell Wilson's lookalike daughter
03:19 Grief, boardroom and the game of succession: Inside family feud tearing through Sona Comstar after Sunjay Kapur’s death- World's largest asset manager BlackRock to employees: You cannot carry your phones and laptops to China, instead …
- Bill Gates says: When your daughter asks if you’d be willing to work a shift in customer service at her startup, the only right answer is ...
- Who is Hulk Hogan’s wife Sky Daily? Age gap, love story, and wedding details
- Shannon Sharpe’s $50M settlement with 20-year-old OnlyFans model takes a shocking new turn as ex-girlfriend gets involved
- Nvidia CEO Jensen Huang: Don't feel sad for my employees, I've created more billionaires on my management team than any CEO, they are doing just ...
Featured in Business
- Backs Powell: 'Central bank independence is essential'
- UPI needs sustainable fin model for long-term viability: RBI governor Sanjay Malhotra
- RBI governor rules out banking licences for corporates
- NSDL IPO: Price band of Rs 760–800 takes investors by surprise; over 20% below unlisted market peak
- Etihad Airways fleet expansion: First Airbus A321LR to enter service Aug 1 on Abu Dhabi-Phuket route; Narrowbody jet features First Suites, wider reach
- Currency watch: Rupee ends 12 paise lower at 86.52 as equities drop and crude rises; trade uncertainty, FIIs weigh
Visual Stories
- 'Dimple Queen' Siddhi Idnani spreads charm in THESE clicks
- Super Dancer 5 judge Shilpa Shetty’s glamorous saree looks
- In pics: Sneha wows in a sareeIn pics: Sneha wows in a saree
- In pics: Stunning looks of Anupama Parameswaran
- Anarkali style guide: Choose the perfect fit for every occasion
- Anna Ben charms in every frame with grace and simplicity
- 10 reasons why a handful of nuts are the ultimate brain food
- 10 Sanskrit baby names with deep philosophical roots
- 10 spine chilling lines from Aldous Huxley’s Brave New World
- 10 poisonous and rare Indian plants
Photostories
- Despite 'popularity' these 5 handloom fabrics are on the verge of extinction
- 10 bedtime habits that help kids sleep better (and wake up happier)
- 6 powerful herbs that can clear brain fog and boost mental clarity
- Leading Bollywood women making waves in the world of business
- 9 expert-approved powerful liver-healthy drinks to make at home
- Garfield to Spiderman: A look at classic comic book characters that made it big in Hollywood
- From shooting 72 hours non-stop for Kasautii Zindagii Kay, Palak's bond with brother Reyaansh to being a strict mom to her daughter; Shweta Tiwari gets candid about life
- NASA tests AI satellite that acts on its own in space; details inside
- Top 5 Telugu TV shows of the week: Karthika Deepam 2 remains at the top
- Saira Banu and her lifelong devotion to Dilip Kumar
Top Trends
Up Next
Start a Conversation
Post comment