6 events in Passaic County with a date

Clorox files suit against IT provider Cogniznat

Hackers got passwords just by asking, case says

By; Raphael Satter
Reuters

WASHINGTON - Bleach maker Clorox said July 22 [2025] that it has sued information technology provider Cognizant over a devastating 2023 attacker, alleging that the hackers pulled off the intrusion simply by asking the tech company's staff for employee's passwords.
..... Clorox was one of several major companies hit in August 2023 by the hacking group dubbed Scattered Spider, which specializes in tricking It help desks into handing over credentials and then suing that access to lock them up for ransom.
..... The group is often described as unusually sophisticated and persistent, but in a case field in California state court on July 22, [2025] Clorox said one of Scattered Spider;s hackers was able to repeatedly steal employees' passwords simply by asking for them.
..... "Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques," according to a copy of the lawsuit reviewed by Reuters.
..... The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox's network, and Cognizant handed the credentials right over."
..... Cognizant, in an emailed statement, pushed back, saying it did not manage cybersecurity for Clorox and it was only hired for limited help desk services.
..... "Clorox has tired to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Congizant reasonably performed," Cognizant said.
..... The suit was not immediately visible on the public docket of the Superior Court of Alameda County, Clorox provided Reuters with a receipt for the lawsuit from the court.
..... Three parity transcripts included in the lawsuit allegedly show conversations between the hacker and cognizant support staff in which the intruder asks to have passwords reset and the support staff complies without verifying who they are talking to. for example, by quizzing them on their employee; identification number or their manager;s name.
..... "I don't have a password, so I can't connect," the hacker says n one call. the agent replies, "Oh, OK. OK. so let me provide the password to you OK?"

HOME