A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA (including the SMS-MFA.
Social Engineering Examples·10 sources
Beginning August 11, 2023, an attacker phoned Cognizant's outsourced IT service desk for Clorox multiple times, impersonating at least two different named Clorox employees (one a regular staffer, one in Clorox's own IT security team). Cognizant's agents allegedly reset the impersonated employees' Okta passwords and Microsoft MFA, and even changed the phone number tied to SMS-based MFA, every time simply because the caller asked, without performing any of the identity-verification steps Clorox says it had specified.
Armed with valid credentials and control of MFA, the attacker gained access to Clorox's corporate network, which Clorox says caused a "debilitating" intrusion: systems were taken offline, manufacturing was paused, and Clorox reverted to manual order processing for weeks, contributing to consumer product shortages. Clorox disclosed the incident via SEC 8-Ks in August and September 2023. Almost two years later, on July 22, 2025, Clorox sued Cognizant in the Superior Court of California, County of Alameda, alleging Cognizant's help-desk failures caused the breach, seeking roughly $380 million in damages, and attaching purported transcripts of the vishing calls as exhibits.
Per Clorox's complaint, a caller ("cybercriminal") phoned Cognizant's outsourced Clorox IT Service Desk claiming to be a specific Clorox employee. When the agent asked how they could help, the caller said something to the effect of "I don't have a password, so I can't connect", and the agent responded "Oh, ok. Ok. So let me provide the password to you ok?" and read out a password beginning with "Welcome...", with zero identity verification (no security questions, no callback, no supervisor check).
The same caller then called back complaining "My Microsoft MFA isn't working," and the agent reset the employee's Microsoft MFA on request ("So multi-factor authentication reset has been done now"). The attacker escalated by also getting the SMS-MFA-linked phone number changed on the account, giving them control of the second authentication factor as well as the password.
Clorox alleges the attacker repeated the tactic against a second employee, this time someone in Clorox's IT security group, with the Cognizant agent proactively offering to reset "two MFA applications" and the caller confirming "Yeah ... reset both of them." With valid credentials and MFA under attacker control, the intruder pivoted into Clorox's Okta-federated corporate network, where the complaint alleges the activity "paralyzed" IT systems.
Lure: a lone phone call pretending to be a real, named Clorox employee locked out of the network, using ordinary IT-support small talk ("I don't have a password, so I can't connect" / "My Microsoft MFA isn't working"); no urgency theatrics or executive-authority claims were even needed. Tell (with hindsight): a caller who cannot answer basic identity-verification questions yet is granted a password reset anyway; two separate credential resets plus a phone-number change for SMS MFA within a short window for the same account; an agent volunteering to reset MFA proactively ("two MFA applications") rather than the caller specifically requesting it, a sign of an agent optimizing for call-resolution speed over verification.
Clorox detected unauthorized activity on the evening of Friday, August 11, 2023, took affected systems offline, and disclosed the incident in an SEC Form 8-K on August 14, 2023. A follow-up 8-K on September 18, 2023 described widescale disruption, reduced order-processing rates, and elevated product-availability issues, with manufacturing resuming at most sites and a return to normal automated order processing targeted for the week of September 25, 2023. Clorox's Q1 FY2024 10-Q (quarter ended Sept. 30, 2023) detailed the same impacts and associated costs.
Nearly two years later, on July 22, 2025, Clorox and Clorox Services Company filed a civil complaint against Cognizant Worldwide Limited and Cognizant Technology Solutions U.S. Corporation in the Superior Court of California, County of Alameda, alleging breach of contract/negligence and seeking roughly $380 million in damages (over $49 million in remediation costs plus hundreds of millions in business-interruption losses), plus punitive damages, interest, fees, and costs.
The complaint, running roughly 87 pages, includes purported call-transcript excerpts as exhibits. As of the filing, the allegations were untested in court; Cognizant had not yet filed a substantive public response noted in press coverage reviewed.
This is one of the clearest, best-documented examples of a high-value breach caused not by malware or a technical exploit but by a single unverified phone call to an outsourced help desk, and it produced court-exhibited transcripts showing exactly how little friction the attacker faced ("So let me provide the password to you ok?"). It illustrates that MFA is only as strong as the reset process behind it: resetting both password and the SMS-MFA-linked phone number in the same call chain defeats MFA entirely without ever touching a token or app.
It also highlights third-party/vendor risk: Clorox had procedures on paper, but enforcement depended entirely on a contracted vendor's front-line staff, and the resulting $380M claim shows how expensive a help-desk verification gap can become. The incident, alongside the broader 2023 wave attributed to Scattered Spider against MGM Resorts, Caesars, and others, cemented help-desk vishing as a top-tier enterprise risk category and is frequently cited in security-awareness and IAM-hardening guidance.
Clorox alleges it had provided Cognizant with "straightforward procedures" to authenticate employees calling the service desk for credential resets, and that Cognizant's agents simply failed to follow them (no knowledge-based verification, no callback to a registered number, no manager/ticket cross-check). Clorox says it detected the intrusion within roughly three hours of initial unauthorized activity and ejected the attacker within five days, but by then the attacker had achieved enough access to force systems offline.
The case is now driving industry emphasis on: mandatory call-back verification to a pre-registered device/number before any credential or MFA reset; supervisor/manager approval or ticket-based identity proofing for high-risk resets (password + MFA together); phone-number-change-to-SMS-MFA treated as a privileged, extra-scrutiny action; recording and auditing all help-desk reset calls; contractual security SLAs and audit rights over outsourced service-desk vendors; and periodic red-team/vishing testing of outsourced help desks.
Social Engineering Examples. “Clorox / Cognizant Help-Desk Pretexting Breach”. Accessed 19 September 2026. https://socialengineeringexamples.com/clorox-cognizant-helpdesk-vishing-2023
Clorox's complaint does not detail how the attacker learned employee names, but Scattered Spider, the group press coverage attributes this intrusion to, is widely reported (Reuters, CSO Online) as specializing in researching target-company staff and identifying which outsourced IT vendor or help desk a company uses, likely how the attacker identified at least two real Clorox employees, a general staffer and a named IT security team member, plausible enough to impersonate convincingly by phone.
Employee-facing OSINT exposure (roles, org charts, and knowledge of which vendor runs a company's help desk) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the reset process it gets used against, rather than trying to hide employee identities.
Per the complaint and exhibited call transcripts, the caller phoned Cognizant's outsourced Clorox Service Desk posing as "Employee 1," claimed to be locked out without a VPN or Okta password, and a Cognizant agent reset the password immediately and read it aloud, with none of the identity-verification steps Clorox says it had specified (self-service tool, manager-name confirmation, or callback).
Mandatory use of a self-service verification tool before any human agent performs a manual reset, or, when self-service is unavailable, a hard requirement to verify manager name plus internal username and send simultaneous confirmation emails to the employee and manager, would have stopped the very first call.
Using the same identity, the caller placed at least three further calls that same day, each time claiming a new MFA problem, and Cognizant agents reset the Microsoft and Okta MFA factors on request every time without ever questioning why the same employee needed repeated resets in such a short window.
Rate-limiting or automatically flagging multiple credential or MFA reset requests for the same account within a short window, and routing them to mandatory supervisor review, closes off the escalation pattern the attacker relied on.
The caller pushed further and asked the agent to change the phone number tied to Employee 1's SMS-based MFA, which the agent also did, giving the attacker full control of both the password and the second authentication factor.
Treating any change to the phone number or device tied to SMS-based MFA as a separate, higher-scrutiny action, such as requiring an out-of-band callback to the previously registered number or manager sign-off, keeps a single phone call from fully taking over both authentication factors.
With Employee 1's password and both MFA factors under attacker control, the intruder logged into Clorox's Okta-federated network and, per the complaint, used that access to identify a second, more privileged target working in Clorox's IT security group.
Conditional-access policies that flag logins from unfamiliar devices, locations, or times even after valid credentials and MFA are presented can catch the moment initial access is used, before an intruder can browse for a second target.
The attacker called the Cognizant service desk again posing as "Employee 2," and across two calls obtained a password reset plus resets of two separate MFA applications, with an agent proactively offering to reset both after noticing two MFA methods on the account, again with no identity verification.
The same help-desk verification controls from Stages 2 through 4 apply regardless of which employee is targeted; treating every reset request as equally high-risk, rather than assuming an IT-security employee's account merits less scrutiny, prevents a repeat of the same playbook against a more privileged target.
Using Employee 2's compromised IT-security-team credentials, the intruder established persistence and moved laterally inside Clorox's environment, expanding from a single compromised account to broader network reach.
Network segmentation and least-privilege access limiting what a single compromised account, even one belonging to IT security staff, can reach, plus monitoring for anomalous lateral movement and privilege use, narrows what an intruder can do even after two accounts are fully compromised.
The intrusion "paralyzed" Clorox's corporate network, per the complaint, forcing systems offline, pausing manufacturing, and requiring weeks of manual order processing; Clorox's public filings and lawsuit do not confirm whether the ultimate goal was data theft, extortion, or disruption itself, only that the business impact was severe enough to underlie a $380 million damages claim.
Rapid detection and containment, which Clorox says it achieved (detecting the intrusion within roughly three hours and ejecting the attacker within five days), plus tested business-continuity and manual-fallback procedures, limits how long a disruptive intrusion can persist; contractual security SLAs, audit rights over outsourced vendors, and periodic vishing red-team testing of the help desk are what would keep the Stage 2 through 6 controls actually enforced by a third party.
Browse by what this case has in common with others in the library.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.