How the Clorox hack happened: attackers who just asked the help desk
According to Clorox, the attackers who shut down its factories in 2023 did not break any encryption or find a clever bug. They phoned the help desk, said they were employees, and were handed new passwords.[1][2] This case file covers what Clorox says happened on those calls, what the attack cost, how its outsourced help desk provider disputes the story, and the one control that would have ended the calls with nothing.
What happened
Clorox, the maker of household cleaning products, had outsourced its IT service desk to Cognizant under an agreement that dated back to 2013.[2] On August 11, 2023, according to a lawsuit Clorox filed two years later, an attacker called that service desk pretending to be a Clorox employee and asked for help getting back into their account.[1][2]
Clorox says the agents reset the caller's password and multifactor login settings without confirming who they were talking to, and that it happened for two employees, one of them in IT security.[1] With those accounts, the attacker got into Clorox's network. Clorox says it expelled the intruder within about 3 hours, but the damage was already done.[2]
The company disclosed the attack publicly in September 2023.[1] Manufacturing was paused, stores ran short of Clorox products, and staff fell back on processing orders by hand for weeks.[1][2]
How they got in
This was social engineering, the art of talking someone into doing the attacker's work for them. Help desks are a natural target: their job is to get locked-out people working again, quickly and politely, and a confident caller with a plausible story can use that helpfulness against the company.
Clorox's complaint, as reported, says its written procedures required agents to check identity before any reset, including using an internal verification tool and confirming details such as the employee's manager and username. It alleges agents skipped those checks, reset access to the company's single sign-on and multifactor systems, changed the phone number used for text-message codes, and did not send the confirmation emails that should have alerted the real employee and their manager.[2] In one call described in the complaint, Clorox says the agent never verified that the caller was the employee at all.[1]
The key point is that resetting multifactor login undoes its protection. If the person who can reset your second factor will do it for a stranger, the second factor only protects against attackers who do not think to call. The attack has been linked in press coverage to a group known for exactly this kind of phone-based deception.[1]
What it cost
Clorox filed suit against Cognizant in California state court on July 22, 2025, seeking $380 million in damages, including about $49 million in direct remediation costs. The rest reflects lost sales and business disruption.[1][2] The claims include breach of contract and gross negligence, and Clorox also says Cognizant misrepresented how well its staff were trained and gave poor help with recovery.[1]
Cognizant rejects the claims. It says it provided only a narrow set of help desk services, was never responsible for Clorox's overall security, and called Clorox's own internal security inept.[1][2] The case was pending when these sources were published, and the allegations have not been proven in court.
The missing control
The missing control: verifying identity before credential resets. Any request to reset a password or multifactor setting should require proof the caller cannot fake from public information, and should trigger a notice to the real employee and their manager.
By Clorox's own account, the procedure existed on paper.[2] What mattered was that it was followed every time, on every call, even when the caller sounded stressed or senior. A callback to the number already on file, a check through a separate verification tool, or a manager's approval would have left the attacker holding nothing. And the notification emails, if sent, would have warned the real employees within minutes that someone else had just taken over their accounts.
What to do in your business
- Never reset access on the strength of a phone call alone. Hang up and call back the number already on file, or confirm through a manager, before changing any password or login method.
- Treat multifactor resets as high-risk. Require a second person's approval or an in-person or video check before a new phone or authenticator is linked to an account.
- Always notify the real user. Make sure every password or multifactor change sends an alert to the account owner and their manager.
- Put the rules in your IT contract. If you outsource IT support, write the identity checks into the agreement and ask for call records or spot checks showing they are followed.
- Protect admin and security staff first. Accounts with broad access should need stronger checks and phishing-resistant keys that a help desk cannot simply reset.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.