this post was submitted on 23 Jul 2025
25 points (100.0% liked)

Cybersecurity

0 readers
7 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
 

Seriously? WTF?

“Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques,” according to a copy of the lawsuit reviewed by Reuters. “The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox’s network, and Cognizant handed the credentials right over.”

https://www.nbcnews.com/business/business-news/lawsuit-says-clorox-hackers-got-passwords-simply-asking-rcna220313

#CyberSecurity #Ransomware #Hacking #SocialEngineering

top 5 comments
sorted by: hot top controversial new old
[–] pdxfed@lemmy.world 9 points 1 day ago* (last edited 14 hours ago)

The approach to limit complexity and scope in jobs to lower the educational or skill requirements (and transparently by companies resulting compensation) guarantees siloed work. Not only to people have a limited understanding of the work they're doing and how it connects but they have NO idea what other people are doing, or why--and that's even within the same department or function.

You know when you accepted the risk, boss?

This is the risk.

[–] MadMadBunny@lemmy.ca 9 points 1 day ago (1 children)
[–] Tar_alcaran@sh.itjust.works 11 points 1 day ago

It's not even "pretend to be the county password Inspector". It's literally just "hi, can I have access?"

[–] debby@hear-me.social 2 points 1 day ago

@Jerry@hear-me.social Even if a door is unbreakable, the walls might not be.
Surprisingly, even the best security measures can be easily overcome by simple social engineering. This case should remind us of the importance of including everyone in a security strategy. It is crucial to consistently teach and explain to all employees why security is important and how to implement best practices at every level of a company. Unfortunately, many companies, like Clorox, fail to educate all employees, leaving themselves wide open to social engineering attacks.