Case file · CLOROX 2023

How the Clorox hack happened: attackers who just asked the help desk

Published 2026-09-29 · 4 min read · Missing control: Verify identity before credential resets

According to Clorox, the attackers who shut down its factories in 2023 did not break any encryption or find a clever bug. They phoned the help desk, said they were employees, and were handed new passwords.[1][2] This case file covers what Clorox says happened on those calls, what the attack cost, how its outsourced help desk provider disputes the story, and the one control that would have ended the calls with nothing.

What happened

Clorox, the maker of household cleaning products, had outsourced its IT service desk to Cognizant under an agreement that dated back to 2013.[2] On August 11, 2023, according to a lawsuit Clorox filed two years later, an attacker called that service desk pretending to be a Clorox employee and asked for help getting back into their account.[1][2]

Clorox says the agents reset the caller's password and multifactor login settings without confirming who they were talking to, and that it happened for two employees, one of them in IT security.[1] With those accounts, the attacker got into Clorox's network. Clorox says it expelled the intruder within about 3 hours, but the damage was already done.[2]

The company disclosed the attack publicly in September 2023.[1] Manufacturing was paused, stores ran short of Clorox products, and staff fell back on processing orders by hand for weeks.[1][2]

How they got in

This was social engineering, the art of talking someone into doing the attacker's work for them. Help desks are a natural target: their job is to get locked-out people working again, quickly and politely, and a confident caller with a plausible story can use that helpfulness against the company.

Clorox's complaint, as reported, says its written procedures required agents to check identity before any reset, including using an internal verification tool and confirming details such as the employee's manager and username. It alleges agents skipped those checks, reset access to the company's single sign-on and multifactor systems, changed the phone number used for text-message codes, and did not send the confirmation emails that should have alerted the real employee and their manager.[2] In one call described in the complaint, Clorox says the agent never verified that the caller was the employee at all.[1]

The key point is that resetting multifactor login undoes its protection. If the person who can reset your second factor will do it for a stranger, the second factor only protects against attackers who do not think to call. The attack has been linked in press coverage to a group known for exactly this kind of phone-based deception.[1]

What it cost

Clorox filed suit against Cognizant in California state court on July 22, 2025, seeking $380 million in damages, including about $49 million in direct remediation costs. The rest reflects lost sales and business disruption.[1][2] The claims include breach of contract and gross negligence, and Clorox also says Cognizant misrepresented how well its staff were trained and gave poor help with recovery.[1]

Cognizant rejects the claims. It says it provided only a narrow set of help desk services, was never responsible for Clorox's overall security, and called Clorox's own internal security inept.[1][2] The case was pending when these sources were published, and the allegations have not been proven in court.

The missing control

The missing control: verifying identity before credential resets. Any request to reset a password or multifactor setting should require proof the caller cannot fake from public information, and should trigger a notice to the real employee and their manager.

By Clorox's own account, the procedure existed on paper.[2] What mattered was that it was followed every time, on every call, even when the caller sounded stressed or senior. A callback to the number already on file, a check through a separate verification tool, or a manager's approval would have left the attacker holding nothing. And the notification emails, if sent, would have warned the real employees within minutes that someone else had just taken over their accounts.

What to do in your business

Watch the case
Clorox says hackers just asked for the passwordsDrops 2026-12-13
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. BleepingComputer: Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit
  2. The Register: Clorox's lawsuit against Cognizant over the 2023 cyberattack