How do hackers get passwords? Sometimes, they just ask.

How do hackers get passwords? Sometimes, they just ask.

Cybersecurity breaches can often appear daunting, yet some hackers exploit surprisingly simple tactics. A recent incident involving The Clorox Company highlights this alarming trend. In 2023, the company fell victim to a significant breach that resulted in an estimated $380 million in damages, all initiated by a seemingly benign phone call. The hacker impersonated a Clorox employee, contacting the IT service desk and requesting a password reset along with multifactor authentication resets for Okta and Microsoft accounts. Astonishingly, the service desk complied without verifying the caller's identity. This lapse in security allowed the hacker to gain access to the network and subsequently impersonate another trusted IT security user. A second call to the service desk led to yet another password reset, further compromising Clorox’s security. Clorox has since filed a lawsuit against Cognizant, the outsourced IT service provider responsible for managing its service desk operations. The lawsuit accuses Cognizant of failing to adhere to even the most basic security protocols, stating that their negligence was a “devastating lie.” According to Clorox, Cognizant's staff lacked adequate training and awareness, allowing the cybercriminal to exploit the service desk without encountering any authentication barriers. Cognizant’s role was to protect Clorox’s network from such breaches, yet the incident underscores a critical vulnerability in cybersecurity practices. The lawsuit asserts that the firm was not misled by sophisticated hacking techniques but rather succumbed to a straightforward social engineering attack, where the hacker simply made a call and received access credentials without any verification. This case serves as a stark reminder of the importance of stringent security measures and training in the ever-evolving landscape of cybersecurity.

Sources : Ars Technica

Published On : Jul 23, 2025, 19:55

AI
The Future of AI: A Utility Bill on the Horizon?

In an intriguing forecast, Sam Altman, CEO of OpenAI, predicts that artificial intelligence may someday be treated as a ...

Business Insider | Mar 13, 2026, 16:00
The Future of AI: A Utility Bill on the Horizon?
AI
Elon Musk Announces Major Overhaul of xAI Following Co-Founder Departures

In a surprising turn of events, Elon Musk has revealed that his artificial intelligence venture, xAI, is undergoing a si...

CNBC | Mar 13, 2026, 18:45
Elon Musk Announces Major Overhaul of xAI Following Co-Founder Departures
Mobile
AT&T Resolves $6,196 Billing Error for FirstNet Customer After Inquiry

If you're a FirstNet user with AT&T and receive an unexpected charge of around $6,200, take heart—it's likely a billing ...

Ars Technica | Mar 13, 2026, 17:50
AT&T Resolves $6,196 Billing Error for FirstNet Customer After Inquiry
Startups
Travis Kalanick Unveils Atoms: A New Venture in Robotics

Travis Kalanick, the founder of Uber, has officially launched his latest enterprise, Atoms, which is set to focus on rob...

TechCrunch | Mar 13, 2026, 19:40
Travis Kalanick Unveils Atoms: A New Venture in Robotics
AI
Job Market Alarm: AI's Impact on New Graduates Could Push Unemployment Rates to Shocking Heights

The rise of artificial intelligence is poised to create significant challenges for recent college graduates as companies...

CNBC | Mar 13, 2026, 16:15
Job Market Alarm: AI's Impact on New Graduates Could Push Unemployment Rates to Shocking Heights
View All News
How do hackers get passwords? Sometimes, they just ask.