After $380M hack, Clorox sues its "service desk" vendor for simply giving out passwords
Briefly

A significant breach occurred at The Clorox Company when a cybercriminal exploited weak IT security measures. By impersonating employees and requesting password resets, the individual gained access to Clorox's network. The breach, attributed to the failure of Cognizant, the service desk provider, resulted in an estimated $380 million in damages. Clorox's lawsuit claims Cognizant did not follow basic procedures to verify identities and allowed unauthorized access, leading to the network compromise. Cognizant is accused of inadequate employee training and negligence in handling sensitive information.
Cognizant's behavior was 'all a devastating lie,' it 'failed to show even scant care,' and it was 'aware that its employees were not adequately trained.'
Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques. The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox's network.
Read at Ars Technica
[
|
]