Clorox CISO flushes self after multi-million-dollar cyberattack
(2023/11/16)
- Reference: 1700095430
- News link: https://www.theregister.co.uk/2023/11/16/clorox_ciso_washes_out/
- Source link:
The Clorox Company's chief security officer has left her job in the wake of a corporate network breach that cost the manufacturer hundreds of millions of dollars.
[1]Amy Bogac held the title of chief information security officer (CISO) and VP of enterprise security and infrastructure at Clorox since June 2021, per her LinkedIn profile.
AlphV files SEC complaint
In other cyber news, affiliates of ransomware gang AlphV (aka [2]BlackCat ) claimed to have compromised digital lending firm MeridianLink – and reportedly filed an SEC complaint against the fintech firm for failing to disclose the intrusion to the US watchdog.
First [3]reported by DataBreaches, the break-in apparently happened on November 7. AlphaV’s operatives claimed they did not encrypt any files but did steal some data – and MeridianLink was allegedly aware of the intrusion the day it occurred.
In screenshots shared with The Register and [4]posted on social media, the AlphaV SEC submission claims MeridianLink made a "material misstatement or omission" in its filings and financial statements, "or a failure to file."
The thoughtful folks at AlphV asserted they are simply filing the paperwork for MeridianLink – and giving it "24 hours before we publish the data in its entirety."
The Register asked the SEC about the AlphV complaint. "We decline to comment," the spokesperson replied.
While her LinkedIn profile doesn't indicate any job changes, Friday was Bogac's [5]last day at the multinational cleaning product conglomerate, according to Bloomberg News, which reviewed an internal memo and cited two people familiar with the matter.
Bogac did not respond to The Register 's inquiries, and a Clorox spokesperson declined to say if Bogac remains on staff.
"Out of respect to our current and former teammates, we do not comment on personnel matters," the spokesperson replied.
[6]
Chau Banks, the chief information and data officer of the $7 billion biz, who reportedly penned the memo, will fill Bogac's role as Clorox continues mopping up the mess searches for and hires a replacement.
[7]
[8]
"She was a champion of cyber security best practices externally and across the company through her ongoing participation in our Lunch With a Leader series to influence and educate others on cyber security awareness and relevant topics," the memo read. "During her time at Clorox, she also developed a strong Security & Infrastructure team."
Clorox first [9]disclosed its computer network had been compromised in a US Securities and Exchange Commission filing in August. At the time, it said some of its IT systems and operations had been "temporarily impaired" due to "unauthorized activity" in its IT environment.
[10]
A subsequent SEC filing in September [11]noted "wide scale disruption" across the business because of the intrusion.
Those disruptions included processing orders by hand after some systems were taken offline. "The company is operating at a lower rate of order processing and has recently begun to experience an elevated level of consumer product availability issues," Clorox said at the time.
[12]The Clorox Company admits cyberattack causing 'widescale disruption'
[13]Clorox cleans up IT security breach that soaked its biz ops
[14]Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land
[15]Ransomware royale: US confirms Royal, BlackSuit are linked
In its first-quarter fiscal 2024 earnings report at the start of this month, Clorox reported a [16]20 percent drop in year-on-year Q1 net sales and noted the $356 million decrease was "driven largely" by the cyberattack.
In a subsequent SEC filing, Clorox noted that expenses related to the network break-in for the three months ending September 30 totaled $24 million.
"The costs incurred relate primarily to third-party consulting services, including IT recovery and forensic experts and other professional services incurred to investigate and remediate the attack, as well as incremental operating costs incurred from the resulting disruption to the company's business operations," according to the [17]Form 10-Q filing.
[18]
Clorox also revealed it expects to incur more expenses related to the security super-snafu in future periods. ®
Get our [19]Tech Resources
[1] https://www.linkedin.com/in/abogac/
[2] https://www.theregister.com/2022/03/22/talos-ransomware-blackcat/
[3] https://www.databreaches.net/alphv-files-an-sec-complaint-against-meridianlink-for-not-disclosing-a-breach-to-the-sec/
[4] https://twitter.com/vxunderground/status/1724910414255825050
[5] https://www.bloomberg.com/news/articles/2023-11-15/clorox-cyber-chief-leaves-as-recovery-from-cyberattack-continues?srnd=technology-vp
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/08/15/clorox_cleans_up_security_breach/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/09/19/the_clorox_company_admits_cyber/
[12] https://www.theregister.com/2023/09/19/the_clorox_company_admits_cyber/
[13] https://www.theregister.com/2023/08/15/clorox_cleans_up_security_breach/
[14] https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/
[15] https://www.theregister.com/2023/11/14/us_confirms_royalblacksuit_ransomware_ties/
[16] https://www.sec.gov/Archives/edgar/data/21076/000002107623000046/ex991-pressreleasedatednov.htm
[17] https://www.sec.gov/ix?doc=/Archives/edgar/data/21076/000002107623000048/clx-20230930.htm
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
[1]Amy Bogac held the title of chief information security officer (CISO) and VP of enterprise security and infrastructure at Clorox since June 2021, per her LinkedIn profile.
AlphV files SEC complaint
In other cyber news, affiliates of ransomware gang AlphV (aka [2]BlackCat ) claimed to have compromised digital lending firm MeridianLink – and reportedly filed an SEC complaint against the fintech firm for failing to disclose the intrusion to the US watchdog.
First [3]reported by DataBreaches, the break-in apparently happened on November 7. AlphaV’s operatives claimed they did not encrypt any files but did steal some data – and MeridianLink was allegedly aware of the intrusion the day it occurred.
In screenshots shared with The Register and [4]posted on social media, the AlphaV SEC submission claims MeridianLink made a "material misstatement or omission" in its filings and financial statements, "or a failure to file."
The thoughtful folks at AlphV asserted they are simply filing the paperwork for MeridianLink – and giving it "24 hours before we publish the data in its entirety."
The Register asked the SEC about the AlphV complaint. "We decline to comment," the spokesperson replied.
While her LinkedIn profile doesn't indicate any job changes, Friday was Bogac's [5]last day at the multinational cleaning product conglomerate, according to Bloomberg News, which reviewed an internal memo and cited two people familiar with the matter.
Bogac did not respond to The Register 's inquiries, and a Clorox spokesperson declined to say if Bogac remains on staff.
"Out of respect to our current and former teammates, we do not comment on personnel matters," the spokesperson replied.
[6]
Chau Banks, the chief information and data officer of the $7 billion biz, who reportedly penned the memo, will fill Bogac's role as Clorox continues mopping up the mess searches for and hires a replacement.
[7]
[8]
"She was a champion of cyber security best practices externally and across the company through her ongoing participation in our Lunch With a Leader series to influence and educate others on cyber security awareness and relevant topics," the memo read. "During her time at Clorox, she also developed a strong Security & Infrastructure team."
Clorox first [9]disclosed its computer network had been compromised in a US Securities and Exchange Commission filing in August. At the time, it said some of its IT systems and operations had been "temporarily impaired" due to "unauthorized activity" in its IT environment.
[10]
A subsequent SEC filing in September [11]noted "wide scale disruption" across the business because of the intrusion.
Those disruptions included processing orders by hand after some systems were taken offline. "The company is operating at a lower rate of order processing and has recently begun to experience an elevated level of consumer product availability issues," Clorox said at the time.
[12]The Clorox Company admits cyberattack causing 'widescale disruption'
[13]Clorox cleans up IT security breach that soaked its biz ops
[14]Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land
[15]Ransomware royale: US confirms Royal, BlackSuit are linked
In its first-quarter fiscal 2024 earnings report at the start of this month, Clorox reported a [16]20 percent drop in year-on-year Q1 net sales and noted the $356 million decrease was "driven largely" by the cyberattack.
In a subsequent SEC filing, Clorox noted that expenses related to the network break-in for the three months ending September 30 totaled $24 million.
"The costs incurred relate primarily to third-party consulting services, including IT recovery and forensic experts and other professional services incurred to investigate and remediate the attack, as well as incremental operating costs incurred from the resulting disruption to the company's business operations," according to the [17]Form 10-Q filing.
[18]
Clorox also revealed it expects to incur more expenses related to the security super-snafu in future periods. ®
Get our [19]Tech Resources
[1] https://www.linkedin.com/in/abogac/
[2] https://www.theregister.com/2022/03/22/talos-ransomware-blackcat/
[3] https://www.databreaches.net/alphv-files-an-sec-complaint-against-meridianlink-for-not-disclosing-a-breach-to-the-sec/
[4] https://twitter.com/vxunderground/status/1724910414255825050
[5] https://www.bloomberg.com/news/articles/2023-11-15/clorox-cyber-chief-leaves-as-recovery-from-cyberattack-continues?srnd=technology-vp
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/08/15/clorox_cleans_up_security_breach/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/09/19/the_clorox_company_admits_cyber/
[12] https://www.theregister.com/2023/09/19/the_clorox_company_admits_cyber/
[13] https://www.theregister.com/2023/08/15/clorox_cleans_up_security_breach/
[14] https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/
[15] https://www.theregister.com/2023/11/14/us_confirms_royalblacksuit_ransomware_ties/
[16] https://www.sec.gov/Archives/edgar/data/21076/000002107623000046/ex991-pressreleasedatednov.htm
[17] https://www.sec.gov/ix?doc=/Archives/edgar/data/21076/000002107623000048/clx-20230930.htm
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVWh@1VCSkg3zO2C1h7gUAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
"Best Practices"
Yorick Hunt
Just like other fads, "best practices" are revised on a seemingly daily basis, as the real world confronts the la-la land of the corporate world.
Rather than investing grey matter into actually locking a network down, it's far easier for those with more titles than qualifications to simply grab off-the-shelf black box solutions, citing (when the inevitable happens) "best practices" as their excuse.
Whether the CISO was dismissed or fell on her own sword is irrelevant; she'll turn up in a similar role at a similar company within weeks if not days. All while being less capable than the average teenage nerd in the realm of network security.
Which Sitch?
Every time I read one of these articles detailing a major breach shortly followed by the firing of the CISO, I always wonder which situation it was:
(1) The CISO said/wrote, "We need to do these things [followed by a list]; it will cost X amount of money," was overruled by the remainder of the C-suiters, who claimed, "That's too much money, so we won't do that," and when the warned-against breach did occur, the CISO was beaten like a sacrificial goat (well, fired), or,
(2) The CISO truly was incompetent.
(Icon for CISO on fire.)