By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: UnixiPublished July 29, 2025

TL;DR: The Clorox-Cognizant breach shows how stolen passwords still provide a direct path into enterprise systems, driving disruption, reputational damage, and a $380 million lawsuit, according to Unixi. The case reinforces a basic identity truth: as long as passwords remain a usable target, attackers retain a scalable entry point and IAM teams inherit avoidable risk.


At a glance

What this is: This is an analysis of the Clorox-Cognizant breach and the broader weakness of password-based access, with the key finding that passwords remain the attacker’s easiest entry point.

Why it matters: It matters because IAM teams still carry the operational burden of password reuse, phishing exposure, and recovery overhead, while passwordless controls can reduce human identity attack surface and simplify governance.

By the numbers:

👉 Read Unixi's analysis of the Clorox-Cognizant breach and passwordless access


Context

Password-based authentication remains one of the most common identity weak points because the secret itself becomes the target. Once a password is phished, reused, or cracked, attackers can often move straight into SaaS, VPN, and privileged workflows without needing to defeat stronger downstream controls.

The Clorox-Cognizant breach is a reminder that this is not a theoretical risk. For IAM programmes, the problem is not simply weak user behaviour, but a design model that still depends on reusable secrets for access to high-value systems.


Key questions

Q: How should organisations phase in passwordless authentication without disrupting access?

A: Start by inventorying every place a password is still used, including recovery and support paths. Then target the highest-risk or highest-friction journeys first, measure user impact, and expand only after assurance and usability remain stable. The goal is a controlled transition, not an overnight replacement of every login method.

Q: Why do passwords still create so much identity risk in modern environments?

A: Passwords remain risky because they are reusable, easy to phish, and often tied to inconsistent user behaviour across many accounts. Once credentials are stolen, attackers can reuse them across services or pivot into reset flows. That is why reducing shared-secret dependence matters more than asking users to manage them better.

Q: What do organisations get wrong when they treat passwordless as a single control?

A: They confuse user convenience with authentication strength. A programme can eliminate passwords in the browser and still rely on weak recovery, email links, OTPs, or passwords in other channels, which means the attack surface is reduced in one place but preserved elsewhere.

Q: Who is accountable when organisations keep relying on passwords after repeated credential-based breaches?

A: Accountability sits with the organisation’s security and identity leadership, because authentication design is a governance decision, not just a technical setting. Teams should assess whether their controls actually verify identity, whether they support phishing resistant MFA, and whether high risk workflows still depend on passwords. If they do, the residual risk remains with the business.


Technical breakdown

Why passwords remain such an efficient attack path

Passwords fail because they are reusable, transferable, and often invisible once compromised. A stolen password can be replayed from a new device, a new network, or a new geography without changing the authentication mechanics that the application trusts. That makes phishing, credential stuffing, and social engineering persistent initial access techniques. In identity terms, the secret is the control surface, and once it leaks, the control collapses into a simple possession test. Modern attackers do not need to break cryptography when they can obtain the credential directly.

Practical implication: reduce the number of systems that still accept reusable passwords, especially for SaaS, privileged access, and external-facing applications.

How passwordless authentication changes the trust model

Passwordless approaches shift the verifier away from shared knowledge and toward cryptographic possession, device binding, or biometric confirmation. Passkeys, hardware tokens, and certificate-based access remove the reusable secret from the user journey, which means there is no password database, no password reuse path, and no password to phish in the usual sense. The technical value is not convenience alone. It is the elimination of a widely exploited secret class that attackers repeatedly convert into account takeover, session hijacking, and support fraud.

Practical implication: prioritise passwordless methods for the highest-risk human identities first, then expand to broader workforce and customer-facing flows.

Why browser-based application coverage still matters

Many organisations have passwordless islands rather than passwordless estates. Browser-based applications remain a major challenge because they are often numerous, legacy-tied, and uneven in authentication support. If users must fall back to passwords for a large application set, the identity programme still preserves the attacker’s easiest path. The architectural issue is therefore coverage, not just capability. A passwordless control only meaningfully changes risk when it becomes the default across the applications that matter most.

Practical implication: inventory browser-based applications that still force password fallback and sequence remediation by business criticality.


Threat narrative

Attacker objective: The attacker’s objective was to gain unauthorized access through the weakest human identity factor and convert it into operational disruption and leverage.

  1. Entry occurred when attackers used compromised passwords to access systems tied to Clorox and Cognizant.
  2. Escalation followed through application and identity trust that accepted the stolen credentials as valid without requiring stronger proof of possession.
  3. Impact included disrupted operations, reputational damage, and a $380 million lawsuit.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Code Formatting Tools Credential Leaks — Widely used code formatting tools cause massive credential and secrets leaks in enterprise environments.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Reusable passwords are a governance failure, not just a user inconvenience. Passwords persist because programmes tolerate shared, replayable secrets as an acceptable access mechanism. That assumption is incompatible with current phishing and credential replay economics, where the secret itself becomes the compromise vector. IAM leaders should treat password dependence as a structural exposure, not a help desk problem.

Passwordless reduces attacker leverage only when it removes fallback paths. Partial deployments create false assurance if critical applications still accept passwords, recovery channels still rely on knowledge factors, or service desks can re-enable weak authentication on demand. The real control question is whether the password remains available anywhere the attacker can reach. Practitioners should measure residual password surface, not just adoption rates.

Identity attack surface now spans human access and downstream NHI trust. Once a human account is compromised, attackers often pivot into tokens, sessions, and service integrations that sit behind that identity. That makes passwordless part of a broader identity containment strategy, not a standalone login upgrade. The practical conclusion is that human authentication, privileged access, and non-human credential governance have to be treated as one chain of trust.

Browser-based application coverage is the named concept teams keep underestimating. Passwordless programmes fail when they are designed for the easiest applications first and the hardest ones later. Browser access to SaaS and internal web apps is where password fallback often persists longest, which preserves the attacker’s most familiar route. Security teams should frame the gap as browser-based application coverage, because incomplete coverage keeps the old threat model alive.

From our research:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • From our research: Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
  • That confidence gap makes passwordless work only as a partial answer unless teams also control recovery paths, OAuth-linked access, and downstream service identity exposure.

What this signals

Passwordless adoption will increasingly be judged by residual exposure, not by enrolment numbers. If a programme still leaves password fallback in recovery, admin bypasses, or browser-based legacy apps, the attacker still has a usable path. That is why identity teams should pair passwordless rollout with a hard inventory of fallback mechanisms and link the programme to Ultimate Guide to NHIs , Key Challenges and Risks where downstream secrets and service accounts remain in scope.

Browser-based application coverage: this is where many passwordless strategies stall, because the long tail of web apps often determines whether the control actually changes risk. The programme signal is simple: if users can still reach high-value systems through passwords, the organisation has not removed the attack surface, only shifted it.

Once human identities are hardened, the next weakness usually appears in connected non-human access. That is where teams should connect passwordless rollout to broader identity governance and review 52 NHI breaches Report for the downstream patterns that emerge after initial access.


For practitioners

  • Eliminate password fallback for privileged users Move administrators, finance users, and high-risk workforce accounts to passwordless authentication before expanding to lower-risk populations. Keep recovery flows aligned so help desk reset paths do not silently reintroduce passwords.
  • Inventory every application that still requires passwords Build a complete list of SaaS, internal web apps, VPNs, and legacy browser-based systems that cannot yet operate without reusable secrets. Prioritise remediation by business criticality and exposure to phishing.
  • Lock down recovery and reset processes Treat account recovery as part of the authentication surface. Require stronger proof for resets, restrict agent overrides, and monitor for repeated reset activity that signals passwordless backsliding.
  • Measure residual password exposure Track how many users, applications, and privileged workflows still depend on passwords after rollout. A passwordless project only changes risk when the remaining password footprint trends toward zero.

Key takeaways

  • Password compromise remains a direct route into enterprise systems, which is why the Clorox-Cognizant breach turned into both operational disruption and major legal exposure.
  • Passwordless only changes security outcomes when it removes fallback paths, recovery exceptions, and browser-based legacy dependencies.
  • IAM teams should treat password elimination as attack-surface reduction, then extend governance to recovery, privileged access, and downstream identity links.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPasswordless and phishing-resistant authentication are central to this article.
NIST Zero Trust (SP 800-207)The article aligns with continuous verification and reduced trust in shared secrets.
NIST CSF 2.0PR.AC-7This article focuses on stronger authentication for access control.

Apply zero trust principles to remove password dependence from access decisions and recovery paths.


Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Phishing-resistant Authenticator: An authentication factor that cannot be easily replayed, proxied, or tricked into disclosure by phishing. In practice, it uses public key cryptography and binds the authentication response to the legitimate origin and transaction context, reducing the value of stolen passwords or repeated prompts.
  • Recovery Path: The set of backup methods, reset flows, and help-desk procedures that restore access when a user loses their primary credential. Recovery paths often become the weakest part of identity governance because they can reintroduce shared secrets, manual override, or inconsistent verification standards.
  • Residual Password Exposure: Residual password exposure is the amount of access that still depends on reusable passwords after a security programme claims progress. It is the clearest way to judge whether a passwordless rollout has actually reduced attack surface or merely shifted it.

What's in the full article

Unixi's full post covers the operational detail this post intentionally leaves for the source:

  • How its Universal SSO approach applies to browser-based applications without application integration.
  • How Key Derived Authentication is positioned to remove stored passwords from the user journey.
  • What the article claims about visibility across SaaS environments and why that matters for deployment planning.
  • Why the vendor frames passwordless access as a response to phishing, reuse, and cracked credentials.

👉 The full Unixi post covers the passwordless model, browser-based application coverage, and the breach lesson it draws from Clorox and Cognizant.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org