Case: Clorox vs. Cognizant – Who’s Responsible for the $380M Help Desk Breach?

Finn Jensen Profile

Finn Jensen | Founder, FastPasscorp

Major consumer goods producer Clorox has sued international service provider Cognizant for $380M following a significant data breach involving Cognizant’s outsourced help desk.

Clorox vs Cognizant Data Breach Blog Image

In essence, Clorox claims that Cognizant failed to properly verify users calling the help desk, which allowed hackers to gain access to user passwords and OKTA MFA credentials.

Cognizant, on the other hand, argues that the breach was caused by Clorox’s lack of overall IT security protections.

This case raises two key questions:

  • When you outsource your help desk—whether to save money or for other reasons, who is responsible if credentials or other sensitive data are leaked to outsiders?
  • How can a workflow be designed to protect user IDs from being stolen through social engineering attacks targeting the help desk?

According to the complaint:

"Cognizant provided the service desk (Service Desk’) that Clorox employees could contact when they needed password recovery or reset assistance.

Cognizant's operation of the Service Desk came with a simple, common-sense requirement: never reset anyone's credentials without properly authenticating them first. Clorox made this easy for Cognizant by providing straightforward procedures to follow whenever providing credential recovery or reset assistance."

However, in 2023, recordings revealed that on August 11 a cybercriminal called Cognizant's Service Desk multiple times, posing as a Clorox employee and requesting password and MFA resets.

"At no point during any of the calls did the Agent verify that the caller was in fact Employee 1.At no point did the Agent follow Clorox's credential support procedures—either the pre-2023 procedure or the January 2023 update—before changing the password for the cybercriminal. The Agent further reset Employee 1's MFA credentials multiple times without any identity verification at all. And at no point did the Agent send the required emails to the employee or the employee's manager to alert them of the password reset," Clorox claims.

This kind of social engineering attack is characteristic of  the Scattered Spider group, which was also behind recent attacks on UK retailers Marks & Spencer and Co-op.

After allegedly failing to verify the caller’s identity, Cognizant reset both the password and multi-factor authentication credentials—giving the hacker full access to Clorox’s IT network.

A transcript of the call between the hacker and help desk has been submitted to the court:

Transcript Hacker and Help Desk Clorox Cognizant

 

Could this happen to your outsourced help desk? Could it happen to your internal help desk?

How to Prevent Social Engineering at the Help Desk

How can service desk teams securely verify a caller in the real world? Companies must balance security with productivity, so the process can’t be overly complex or time-consuming.

If you understand social engineering, you know that hackers’ first strategy is to avoid any identity checks at all. They manipulate the agent into helping them immediately—making it feel like the right thing to do—even if the agent skips verification procedures.

The only way to truly prevent this behavior is with a mandatory workflow. If an agent is unable to reset a password or trigger MFA through Windows or other tools, they must follow a secure workflow to proceed. The simplest method is to remove the agents’ privileges—so even the most convincing hacker can’t succeed.

Second, you need a proofing process that only the real user can pass. This is easier said than done. When a user has lost access to their MFA or forgotten their password, you can’t just send a verification code over the corporate network—they no longer have access.

If the user still has their MFA (Okta, Duo, Microsoft Authenticator, etc.), that should be used—but often, more proof is needed. While it has a mixed reputation—often associated with easily guessed information like pet names or birthdates—it is frequently misunderstood. Many think only of static data like birthdays or pet names—easily guessed from social media.

But our FastPass Identity Verification Manager implementations show that every organization has dynamic data that can help validate users. This could include data from Active Directory (AD/Entra), ITSM systems like ServiceNow, asset management, HR, or production systems. When you combine 2–5 questions with dynamic, user-specific data, only the real user can provide the correct answers.

Conclusion: You Can Prevent Identity Theft at the Help Desk

Contact FastPassCorp to learn how you can quickly implement a secure verification workflow for your help desks.

Related Posts

Scroll to Top