Skip to content
cisonews.net

Incident · 8-K Item 8.01

Clorox reports unauthorized IT activity that damaged infrastructure and disrupted operations

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

The Clorox Company disclosed on August 14, 2023 that it had identified unauthorized activity on some of its IT systems and had taken certain systems offline. Five weeks later it said the attack had damaged parts of its infrastructure and would have a material effect on its fiscal first-quarter results.

August 14 filing

Clorox put workarounds in place for offline operations and said the incident had disrupted, and would continue to disrupt, parts of the business. The investigation was at an early stage.

September 18 update

The second filing described the damage and the knock-on effect on supply. Clorox had moved to manual ordering at a reduced rate and was seeing more product availability problems in stores. It expected to start returning to automated order processing in the week of September 25. The financial view had firmed.

Not in the filings

Neither filing gives a detection date, describes how the attackers got in, or says whether data was taken.

Sources

  1. 2023-08-14 · AThe Clorox Company, Form 8-K (SEC EDGAR), published August 14, 2023
  2. 2023-09-18 · AThe Clorox Company, Form 8-K (SEC EDGAR), published September 18, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.