The Clorox Company disclosed a cyberattack in August 2023 that disrupted its operations, delayed order processing and produced what the company described as significant product outages. In a subsequent securities filing it put the costs incurred at $49 million as of 31 December 2023.
Those costs are stated as relating primarily to third-party consulting — IT recovery and forensics — together with incremental operating expenses arising from the disruption.
The $49 Million Is The Smaller Number
What that figure measures is the cost of responding. It does not measure the sales that did not happen, and Clorox separately reported that the attack weighed on net sales and earnings and expected effects to carry into the following fiscal year.
This is the same accounting distinction the corpus files at 25-0430 for the Co-op and at 23-0110 for Royal Mail. Incident cost, revenue loss and harm to third parties are three different quantities, and public reporting almost always gives only the first.
A Consumer Goods Company Is An Availability Target
No health record, no payment card and no identity document is central to this file. The harm was that a manufacturer could not take orders, make product or ship it, and retailers and consumers downstream absorbed the consequence.
The corpus argues at 24-1231 that availability harm is systematically under-recorded because no notification regime asks for it. Clorox is a useful counterexample only because securities disclosure obligations forced a number into the open — the same mechanism the corpus credits at 25-0924b.
The Route In Is Not Established Here
This file does not assert how the attackers got in. Reporting at the time discussed social engineering against IT support, and the company later pursued litigation against a service provider, but a filed claim is an allegation and this desk does not record allegations as vectors.
Built on reporting of Clorox’s securities filings covering the incident and the $49 million cost figure. That figure is the company’s own statement of costs incurred to a stated date, not a total cost of the incident and not a measure of harm to anyone else. The initial access route is recorded as not established: subsequent litigation between Clorox and a service provider contains allegations, and this desk does not convert a pleading into a finding. No actor attribution is made. Graded high on the disruption and the reported cost. Corrections: corrections@forensicpost.com.
- Clorox says it incurred $49M in costs from 2023 cyberattackCybersecurity Dive
- Clorox Says Cyberattack Costs Exceed $49 MillionSecurityWeek