Case Library / Pretexting & Impersonation / Clorox / Cognizant Help-Desk Pretexting Breach

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning August 11, 2023, an attacker phoned Cognizant's outsourced IT service desk for Clorox multiple times, impersonating at least two different named Clorox employees (one a regular staffer, one in Clorox's own IT security team). Cognizant's agents allegedly reset the impersonated employees' Okta passwords and Microsoft MFA, and even changed the phone number tied to SMS-based MFA, every time simply because the caller asked, without performing any of the identity-verification steps Clorox says it had specified. Armed with valid credentials and control of MFA, the attacker gained access to Clorox's corporate network, which Clorox says caused a "debilitating" intrusion: systems were taken offline, manufacturing was paused, and Clorox reverted to manual order processing for weeks, contributing to consumer product shortages. Clorox disclosed the incident via SEC 8-Ks in August and September 2023. Almost two years later, on July 22, 2025, Clorox sued Cognizant in the Superior Court of California, County of Alameda, alleging Cognizant's help-desk failures caused the breach, seeking roughly $380 million in damages, and attaching purported transcripts of the vishing calls as exhibits.

How the Attack Worked

Per Clorox's complaint, a caller ("cybercriminal") phoned Cognizant's outsourced Clorox IT Service Desk claiming to be a specific Clorox employee. When the agent asked how they could help, the caller said something to the effect of "I don't have a password, so I can't connect", and the agent responded "Oh, ok. Ok. So let me provide the password to you ok?" and read out a password beginning with "Welcome...", with zero identity verification (no security questions, no callback, no supervisor check). The same caller then called back complaining "My Microsoft MFA isn't working," and the agent reset the employee's Microsoft MFA on request ("So multi-factor authentication reset has been done now"). The attacker escalated by also getting the SMS-MFA-linked phone number changed on the account, giving them control of the second authentication factor as well as the password. Clorox alleges the attacker repeated the tactic against a second employee, this time someone in Clorox's IT security group, with the Cognizant agent proactively offering to reset "two MFA applications" and the caller confirming "Yeah ... reset both of them." With valid credentials and MFA under attacker control, the intruder pivoted into Clorox's Okta-federated corporate network, where the complaint alleges the activity "paralyzed" IT systems.

The Lure & the Tell

Lure: a lone phone call pretending to be a real, named Clorox employee locked out of the network, using ordinary IT-support small talk ("I don't have a password, so I can't connect" / "My Microsoft MFA isn't working"); no urgency theatrics or executive-authority claims were even needed. Tell (with hindsight): a caller who cannot answer basic identity-verification questions yet is granted a password reset anyway; two separate credential resets plus a phone-number change for SMS MFA within a short window for the same account; an agent volunteering to reset MFA proactively ("two MFA applications") rather than the caller specifically requesting it, a sign of an agent optimizing for call-resolution speed over verification.

Outcome

Clorox detected unauthorized activity on the evening of Friday, August 11, 2023, took affected systems offline, and disclosed the incident in an SEC Form 8-K on August 14, 2023. A follow-up 8-K on September 18, 2023 described widescale disruption, reduced order-processing rates, and elevated product-availability issues, with manufacturing resuming at most sites and a return to normal automated order processing targeted for the week of September 25, 2023. Clorox's Q1 FY2024 10-Q (quarter ended Sept. 30, 2023) detailed the same impacts and associated costs. Nearly two years later, on July 22, 2025, Clorox and Clorox Services Company filed a civil complaint against Cognizant Worldwide Limited and Cognizant Technology Solutions U.S. Corporation in the Superior Court of California, County of Alameda, alleging breach of contract/negligence and seeking roughly $380 million in damages (over $49 million in remediation costs plus hundreds of millions in business-interruption losses), plus punitive damages, interest, fees, and costs. The complaint, running roughly 87 pages, includes purported call-transcript excerpts as exhibits. As of the filing, the allegations were untested in court; Cognizant had not yet filed a substantive public response noted in press coverage reviewed.

Why It Matters

This is one of the clearest, best-documented examples of a high-value breach caused not by malware or a technical exploit but by a single unverified phone call to an outsourced help desk, and it produced court-exhibited transcripts showing exactly how little friction the attacker faced ("So let me provide the password to you ok?"). It illustrates that MFA is only as strong as the reset process behind it: resetting both password and the SMS-MFA-linked phone number in the same call chain defeats MFA entirely without ever touching a token or app. It also highlights third-party/vendor risk: Clorox had procedures on paper, but enforcement depended entirely on a contracted vendor's front-line staff, and the resulting $380M claim shows how expensive a help-desk verification gap can become. The incident, alongside the broader 2023 wave attributed to Scattered Spider against MGM Resorts, Caesars, and others, cemented help-desk vishing as a top-tier enterprise risk category and is frequently cited in security-awareness and IAM-hardening guidance.

Defenses

Clorox alleges it had provided Cognizant with "straightforward procedures" to authenticate employees calling the service desk for credential resets, and that Cognizant's agents simply failed to follow them (no knowledge-based verification, no callback to a registered number, no manager/ticket cross-check). Clorox says it detected the intrusion within roughly three hours of initial unauthorized activity and ejected the attacker within five days, but by then the attacker had achieved enough access to force systems offline. The case is now driving industry emphasis on: mandatory call-back verification to a pre-registered device/number before any credential or MFA reset; supervisor/manager approval or ticket-based identity proofing for high-risk resets (password + MFA together); phone-number-change-to-SMS-MFA treated as a privileged, extra-scrutiny action; recording and auditing all help-desk reset calls; contractual security SLAs and audit rights over outsourced service-desk vendors; and periodic red-team/vishing testing of outsourced help desks.

Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: Clorox's complaint does not detail how the attacker learned employee names, but Scattered Spider, the group press coverage attributes this intrusion to, is widely reported (Reuters, CSO Online) as specializing in researching target-company staff and identifying which outsourced IT vendor or help desk a company uses, likely how the attacker identified at least two real Clorox employees, a general staffer and a named IT security team member, plausible enough to impersonate convincingly by phone.
Countering Stage 1: Employee-facing OSINT exposure (roles, org charts, and knowledge of which vendor runs a company's help desk) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the reset process it gets used against, rather than trying to hide employee identities.
2
Initial vishing call and password reset: Per the complaint and exhibited call transcripts, the caller phoned Cognizant's outsourced Clorox Service Desk posing as "Employee 1," claimed to be locked out without a VPN or Okta password, and a Cognizant agent reset the password immediately and read it aloud, with none of the identity-verification steps Clorox says it had specified (self-service tool, manager-name confirmation, or callback).
Countering Stage 2: Mandatory use of a self-service verification tool before any human agent performs a manual reset, or, when self-service is unavailable, a hard requirement to verify manager name plus internal username and send simultaneous confirmation emails to the employee and manager, would have stopped the very first call.
3
MFA reset escalation via repeat calls: Using the same identity, the caller placed at least three further calls that same day, each time claiming a new MFA problem, and Cognizant agents reset the Microsoft and Okta MFA factors on request every time without ever questioning why the same employee needed repeated resets in such a short window.
Countering Stage 3: Rate-limiting or automatically flagging multiple credential or MFA reset requests for the same account within a short window, and routing them to mandatory supervisor review, closes off the escalation pattern the attacker relied on.
4
Second-factor takeover via SMS-MFA phone number change: The caller pushed further and asked the agent to change the phone number tied to Employee 1's SMS-based MFA, which the agent also did, giving the attacker full control of both the password and the second authentication factor.
Countering Stage 4: Treating any change to the phone number or device tied to SMS-based MFA as a separate, higher-scrutiny action, such as requiring an out-of-band callback to the previously registered number or manager sign-off, keeps a single phone call from fully taking over both authentication factors.
5
Initial access and internal reconnaissance: With Employee 1's password and both MFA factors under attacker control, the intruder logged into Clorox's Okta-federated network and, per the complaint, used that access to identify a second, more privileged target working in Clorox's IT security group.
Countering Stage 5: Conditional-access policies that flag logins from unfamiliar devices, locations, or times even after valid credentials and MFA are presented can catch the moment initial access is used, before an intruder can browse for a second target.
6
Repeat vishing against a second, higher-value target: The attacker called the Cognizant service desk again posing as "Employee 2," and across two calls obtained a password reset plus resets of two separate MFA applications, with an agent proactively offering to reset both after noticing two MFA methods on the account, again with no identity verification.
Countering Stage 6: The same help-desk verification controls from Stages 2 through 4 apply regardless of which employee is targeted; treating every reset request as equally high-risk, rather than assuming an IT-security employee's account merits less scrutiny, prevents a repeat of the same playbook against a more privileged target.
7
Privilege escalation, persistence, and lateral movement: Using Employee 2's compromised IT-security-team credentials, the intruder established persistence and moved laterally inside Clorox's environment, expanding from a single compromised account to broader network reach.
Countering Stage 7: Network segmentation and least-privilege access limiting what a single compromised account, even one belonging to IT security staff, can reach, plus monitoring for anomalous lateral movement and privilege use, narrows what an intruder can do even after two accounts are fully compromised.
8
Objective completion and impact: The intrusion "paralyzed" Clorox's corporate network, per the complaint, forcing systems offline, pausing manufacturing, and requiring weeks of manual order processing; Clorox's public filings and lawsuit do not confirm whether the ultimate goal was data theft, extortion, or disruption itself, only that the business impact was severe enough to underlie a $380 million damages claim.
Countering Stage 8: Rapid detection and containment, which Clorox says it achieved (detecting the intrusion within roughly three hours and ejecting the attacker within five days), plus tested business-continuity and manual-fallback procedures, limits how long a disruptive intrusion can persist; contractual security SLAs, audit rights over outsourced vendors, and periodic vishing red-team testing of the help desk are what would keep the Stage 2 through 6 controls actually enforced by a third party.
Quick Facts
Victim
The Clorox Company and Clorox Services Company (via its outsourced IT service-desk vendor, Cognizant Technology Solutions / Cognizant Worldwide Limited)
Location
Oakland, California (Clorox headquarters); help desk operated by Cognizant (based in the U.S./India) on Clorox's behalf
Date
2023-08-11 (attack); 2023-08-14 and 2023-09-18 (SEC 8-K disclosures); 2025-07-22 (lawsuit filed)
Impact
Clorox alleges total damages of approximately $380 million, including more than $49 million in remedial/remediation costs plus "hundreds of millions of dollars" in business-interruption losses from lost sales, paused manufacturing, and weeks of manual order processing. These figures are Clorox's pleaded damages claim in active litigation, not a court-awarded or independently audited amount.
Status
Confirmed
Case Type
Real-World Incident
Sector
Retail & E-commerce, Technology & Software
Threat Actor
Organized Crime
Related

Related Cases

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since…

Incident 2023Read →

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…

Incident 2023Read →