The Register Home Page

back to article $380M lawsuit claims intruder got Clorox's passwords from Cognizant simply by asking

Clorox is suing its service desk provider, Cognizant, for $380 million in a California state court, alleging the IT support crew "enabled a cybercriminal to gain a foothold in Clorox's network" by handing over staffers' passwords to attackers after they simply requested them. Someone holding up two bottles of Clorox in a store …

  1. tfewster
    Facepalm

    Deflecting your failures and victim blaming? Classy, Cognizant.

  2. Anonymous Coward
    Anonymous Coward

    Password

    But bro, i don't have access to my authenticator because i lost my phone. Help me out bro

    1. Kevin McMurtrie Silver badge

      Re: Password

      That worked for e-trade some time back. They recommended a Symantec 2FA app that prohibited backups. It locked people out so often they they'd do a login reset without much of an identity challenge.

      1. Kurgan Silver badge

        Re: Password

        Symantec, enough said.

    2. Anonymous Coward
      Anonymous Coward

      Re: Password

      … and if asking doesn’t get a password paying offshored staff in India a bung most certainly works.

  3. SCP

    "... took over an hour to complete a task ..."

    Can't say I am overly impressed by ths claim. If Cognizant were (and should have been) aware that a severe security compromise was in play then it seems reasonable that they would be especially cautious about making any rushed decisions about installing software and this would seem a prudent and proper thing.

    Cognizant look to have had some very serious failings, but why load up the legal suit with this sort of trivia? It seems to be the sort of thing that makes lawyers so widely despised.

  4. Ace2 Silver badge

    What do they claim Clorox should have done to protect against them just giving out fresh passwords?

  5. xanadu42
    Facepalm

    Is this a Security Bleach?

    1. David 132 Silver badge

      The lawyers’ll wipe the floor with them and take them to the cleaners.

  6. An_Old_Dog Silver badge

    ATTENTION: Boards of Directors!

    The lesson you should learn from this example is, "Don't outsource to the cheapest outfit you can find -- nor to an outfit owned by a board member's relly or special friend."

    (Cue startled, shocked, and angry looks by members of boards of directors at this. The angry looks come from those riding the graft gravy-train.)

  7. Anonymous Coward
    Anonymous Coward

    Someone persuaded a Co-op Bank telephone banking service to change both the email address and mobile number associated with my accounts in a single phone call. It took me an hour on the phone to get it sorted.

    The following day the same thing happened again. I no longer bank there.

  8. SirWired 1

    Cognizant's Competitors Just Got a Gift

    It's no surprise to anyone that cheap IT outsourcing sucks, and that you get what you pay for. But that response by their *PR* rep? Holy *bleep!*. "If your IT security was better, it wouldn't have been a problem when our agents handed out password and MFA resets just for asking!"

    The utterly anodyne "We don't comment on ongoing litigation" would have been about 100x better.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like