A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA phone number) with no identity checks at all, giving an intruder the foothold that paralyzed Clorox's network for weeks and is now the subject of a $380 million lawsuit against Cognizant.
Reviewed by the Social Engineering Examples team.
Beginning August 11, 2023, an attacker phoned Cognizant's outsourced IT service desk for Clorox multiple times, impersonating at least two different named Clorox employees (one a regular staffer, one in Clorox's own IT security team). Cognizant's agents allegedly reset the impersonated employees' Okta passwords and Microsoft MFA, and even changed the phone number tied to SMS-based MFA, every time simply because the caller asked, without performing any of the identity-verification steps Clorox says it had specified. Armed with valid credentials and control of MFA, the attacker gained access to Clorox's corporate network, which Clorox says caused a "debilitating" intrusion: systems were taken offline, manufacturing was paused, and Clorox reverted to manual order processing for weeks, contributing to consumer product shortages. Clorox disclosed the incident via SEC 8-Ks in August and September 2023. Almost two years later, on July 22, 2025, Clorox sued Cognizant in the Superior Court of California, County of Alameda, alleging Cognizant's help-desk failures caused the breach, seeking roughly $380 million in damages, and attaching purported transcripts of the vishing calls as exhibits.
Per Clorox's complaint, a caller ("cybercriminal") phoned Cognizant's outsourced Clorox IT Service Desk claiming to be a specific Clorox employee. When the agent asked how they could help, the caller said something to the effect of "I don't have a password, so I can't connect", and the agent responded "Oh, ok. Ok. So let me provide the password to you ok?" and read out a password beginning with "Welcome...", with zero identity verification (no security questions, no callback, no supervisor check). The same caller then called back complaining "My Microsoft MFA isn't working," and the agent reset the employee's Microsoft MFA on request ("So multi-factor authentication reset has been done now"). The attacker escalated by also getting the SMS-MFA-linked phone number changed on the account, giving them control of the second authentication factor as well as the password. Clorox alleges the attacker repeated the tactic against a second employee, this time someone in Clorox's IT security group, with the Cognizant agent proactively offering to reset "two MFA applications" and the caller confirming "Yeah ... reset both of them." With valid credentials and MFA under attacker control, the intruder pivoted into Clorox's Okta-federated corporate network, where the complaint alleges the activity "paralyzed" IT systems.
Lure: a lone phone call pretending to be a real, named Clorox employee locked out of the network, using ordinary IT-support small talk ("I don't have a password, so I can't connect" / "My Microsoft MFA isn't working"); no urgency theatrics or executive-authority claims were even needed. Tell (with hindsight): a caller who cannot answer basic identity-verification questions yet is granted a password reset anyway; two separate credential resets plus a phone-number change for SMS MFA within a short window for the same account; an agent volunteering to reset MFA proactively ("two MFA applications") rather than the caller specifically requesting it, a sign of an agent optimizing for call-resolution speed over verification.
Clorox detected unauthorized activity on the evening of Friday, August 11, 2023, took affected systems offline, and disclosed the incident in an SEC Form 8-K on August 14, 2023. A follow-up 8-K on September 18, 2023 described widescale disruption, reduced order-processing rates, and elevated product-availability issues, with manufacturing resuming at most sites and a return to normal automated order processing targeted for the week of September 25, 2023. Clorox's Q1 FY2024 10-Q (quarter ended Sept. 30, 2023) detailed the same impacts and associated costs. Nearly two years later, on July 22, 2025, Clorox and Clorox Services Company filed a civil complaint against Cognizant Worldwide Limited and Cognizant Technology Solutions U.S. Corporation in the Superior Court of California, County of Alameda, alleging breach of contract/negligence and seeking roughly $380 million in damages (over $49 million in remediation costs plus hundreds of millions in business-interruption losses), plus punitive damages, interest, fees, and costs. The complaint, running roughly 87 pages, includes purported call-transcript excerpts as exhibits. As of the filing, the allegations were untested in court; Cognizant had not yet filed a substantive public response noted in press coverage reviewed.
This is one of the clearest, best-documented examples of a high-value breach caused not by malware or a technical exploit but by a single unverified phone call to an outsourced help desk, and it produced court-exhibited transcripts showing exactly how little friction the attacker faced ("So let me provide the password to you ok?"). It illustrates that MFA is only as strong as the reset process behind it: resetting both password and the SMS-MFA-linked phone number in the same call chain defeats MFA entirely without ever touching a token or app. It also highlights third-party/vendor risk: Clorox had procedures on paper, but enforcement depended entirely on a contracted vendor's front-line staff, and the resulting $380M claim shows how expensive a help-desk verification gap can become. The incident, alongside the broader 2023 wave attributed to Scattered Spider against MGM Resorts, Caesars, and others, cemented help-desk vishing as a top-tier enterprise risk category and is frequently cited in security-awareness and IAM-hardening guidance.
Clorox alleges it had provided Cognizant with "straightforward procedures" to authenticate employees calling the service desk for credential resets, and that Cognizant's agents simply failed to follow them (no knowledge-based verification, no callback to a registered number, no manager/ticket cross-check). Clorox says it detected the intrusion within roughly three hours of initial unauthorized activity and ejected the attacker within five days, but by then the attacker had achieved enough access to force systems offline. The case is now driving industry emphasis on: mandatory call-back verification to a pre-registered device/number before any credential or MFA reset; supervisor/manager approval or ticket-based identity proofing for high-risk resets (password + MFA together); phone-number-change-to-SMS-MFA treated as a privileged, extra-scrutiny action; recording and auditing all help-desk reset calls; contractual security SLAs and audit rights over outsourced service-desk vendors; and periodic red-team/vishing testing of outsourced help desks.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since…
A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…