TL;DR: The Clorox-Cognizant breach shows how stolen passwords still provide a direct path into enterprise systems, driving disruption, reputational damage, and a $380 million lawsuit, according to Unixi. The case reinforces a basic identity truth: as long as passwords remain a usable target, attackers retain a scalable entry point and IAM teams inherit avoidable risk.
NHIMG editorial — based on content published by Unixi: the Clorox-Cognizant breach and the case for passwordless access
By the numbers:
- The Clorox-Cognizant breach led to a $380 million lawsuit.
- Hackers exploit exposed AWS credentials in an average of 17 minutes after public disclosure.
Questions worth separating out
Q: How should organisations phase in passwordless authentication without disrupting access?
A: Start by inventorying every place a password is still used, including recovery and support paths.
Q: Why do passwords still create so much identity risk in modern environments?
A: Passwords remain risky because they are reusable, easy to phish, and often tied to inconsistent user behaviour across many accounts.
Q: What do organisations get wrong when they treat passwordless as a single control?
A: They confuse user convenience with authentication strength.
Practitioner guidance
- Eliminate password fallback for privileged users Move administrators, finance users, and high-risk workforce accounts to passwordless authentication before expanding to lower-risk populations.
- Inventory every application that still requires passwords Build a complete list of SaaS, internal web apps, VPNs, and legacy browser-based systems that cannot yet operate without reusable secrets.
- Lock down recovery and reset processes Treat account recovery as part of the authentication surface.
What's in the full article
Unixi's full post covers the operational detail this post intentionally leaves for the source:
- How its Universal SSO approach applies to browser-based applications without application integration.
- How Key Derived Authentication is positioned to remove stored passwords from the user journey.
- What the article claims about visibility across SaaS environments and why that matters for deployment planning.
- Why the vendor frames passwordless access as a response to phishing, reuse, and cracked credentials.
👉 Read Unixi's analysis of the Clorox-Cognizant breach and passwordless access →
Passwords, phishing, and passwordless access: are your controls keeping up?
Explore further
Reusable passwords are a governance failure, not just a user inconvenience. Passwords persist because programmes tolerate shared, replayable secrets as an acceptable access mechanism. That assumption is incompatible with current phishing and credential replay economics, where the secret itself becomes the compromise vector. IAM leaders should treat password dependence as a structural exposure, not a help desk problem.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
A question worth separating out:
A: Accountability sits with the organisation’s security and identity leadership, because authentication design is a governance decision, not just a technical setting. Teams should assess whether their controls actually verify identity, whether they support phishing resistant MFA, and whether high risk workflows still depend on passwords. If they do, the residual risk remains with the business.
👉 Read our full editorial: Passwordless access is the real lesson from the Clorox-Cognizant breach