> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords

[SOURCE] Ars Technica Security [AUTHOR: Nate Anderson] [DATE: 23/07/2025 19:46] [LANGUAGE: EN]
After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords
Hacking is hard. Well, sometimes. Other times, you just call up a company’s IT service desk and pretend to be an employee who needs a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset… and it’s done. Without even verifying your identity. So you use that information to log in to the target network and discover a more trusted user who works in IT security. You call the IT service desk back, acting like you are now this second person, and you request the same thing: a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset. Again, the desk provides it, no identity verification needed.Read full article Comments
[messages.read_original_source] →