this post was submitted on 23 Jul 2025
67 points (100.0% liked)

Facepalm

3348 readers
4 users here now

founded 2 years ago
MODERATORS
 

“Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques,” according to a copy of the lawsuit reviewed by Reuters. “The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox’s network, and Cognizant handed the credentials right over.”

https://www.nbcnews.com/business/business-news/lawsuit-says-clorox-hackers-got-passwords-simply-asking-rcna220313

top 10 comments
sorted by: hot top controversial new old
[–] Death_Equity@lemmy.world 27 points 1 week ago (3 children)

It is easier to gain access by conning the right person into giving you access than pretty much any other means.

[–] statler_waldorf@sopuli.xyz 3 points 1 week ago

Kevin Mitnick's book is full of this.

[–] Darkassassin07@lemmy.ca 3 points 1 week ago* (last edited 1 week ago) (1 children)

Social engineering is definitely the number one way to gain access, but it should take a bit more effort than just directly asking; 'hey, can I have your password?'

[–] Death_Equity@lemmy.world 1 points 1 week ago

You can go almost anywhere with a scuffed hard hat, dirty high vis vest, a ladder, worn tool belt, and a clip board.

You can get a lot of people to give you their user login and password with the right email and professional format.

The fact that there are people out there who scam people into giving them thousands of dollars in iTunes cards, gift cards, etc. with a threatening phone call claiming to be the IRS or police should tell you that the appearance of authority is a powerful persuasive tool that can convince a lot of the population to go against logic and reason to do what you want.

I don't know if you are old enough to remember the Nigerian Prince email scam, but they only had to include spelling or grammar errors to weed out anyone smart enough to be immune to their grift.

50% of people in the US are below the average IQ of 97.4. 14% have an IQ of 70-85 and they work at every company and will fall for scams without much effort.

So yes, people will just give you a password and username if you ask them the right way.

[–] ReachMinusOne@lemmy.zip 1 points 1 week ago (1 children)

In high school, some friends essentially did the same thing. They fired up the tech support chat, using a real customer's username that the company included in a screenshot on the homepage as part of their product demo, and told support they needed them to send over the password because so-and-so was out of the office and they needed access. Support sent along full credentials. The software in question was a messaging app that my friends wanted to use on the school computers to chat while in class. Very innocuous, and no real harm or national security concerns.

FBI eventually got involved, and friends got put on double secret probation at school as a result. The dean of students later made an announcement at an assembly that he recently had to expel two students for "sending an email to California", all this while I was actively sitting next to one of said "expelled" students during the assembly.

Since they were both minors at the time, no real long-term issues came from it. One even worked for the feds for a while after college.

[–] Death_Equity@lemmy.world 1 points 1 week ago

Yeah, using government property for a crime is generally not a smart idea. Lol

[–] CannedYeet@lemmy.world 18 points 1 week ago

Clorox said the clean-up was hampered by other failures by Cognizant’s staff, including failure to de-activate certain accounts or properly restore data.

They snuck this in the last paragraph.

[–] 1D10@lemmy.world 8 points 1 week ago

That's ironic.

[–] kewjo@lemmy.world 5 points 1 week ago

having worked with cognizant contractors before this is pretty on brand

[–] reddit_sux@lemmy.world 3 points 1 week ago

It seems that this is not the first time some had asked for password. Perhaps was the first time the hacker asked for it.