Clorox told the SEC on 14 August 2023 that it had identified unauthorized activity on some of its IT systems and taken systems offline to contain it. The disclosure was brief and unremarkable. What it set in motion was not: for weeks, one of America's most recognisable consumer-goods companies fell back to manual order processing, and its products — bleach, wipes, cleaning supplies — thinned out on US retail shelves. Clorox said it expected to begin returning to automated order processing only in the week of 25 September.

How it began is best described in Clorox's own words, filed in a lawsuit two years later. According to that July 2025 complaint, on 11 August 2023 a caller reached the service desk operated by its IT provider, Cognizant, said they could not get to the VPN, and asked for a password reset on Clorox's Okta identity system. The agent reset it. The complaint alleges no verification of the caller's identity took place. Cognizant has publicly rejected the claim, saying it was hired for "a narrow scope of help desk services" and calling the allegations baseless — so this remains a contested matter between two companies, not a settled account. The intrusion is widely reported, and alleged in Clorox's complaint, as the work of the English-speaking crew tracked as Scattered Spider; Clorox itself named no attacker in its 2023 filings.

The financial record deserves precision, because the widely-quoted number is often misused. Clorox reported $49 million in costs directly attributable to the attack as of 31 December 2023. Separately, net sales for the quarter ended 30 September 2023 fell about 20% — a decline of roughly $356 million that the company attributed largely to the attack. That $356 million is lost revenue, not a cyber-incident cost line. And the $380 million figure in circulation is damages sought in the 2025 lawsuit, not a booked loss.

Strip away the numbers and August 2023 delivered the decade's cleanest demonstration of a truth security spending resists: the most effective attack technique available required no technical skill at all. Somebody phoned, and somebody helpful said yes.

Also that month · The spreadsheet

Every police officer in Northern Ireland, published by accident

On 8 August at around half past two in the afternoon, the Police Service of Northern Ireland answered a freedom-of-information request about officer numbers by publishing an Excel file. A tab in that file carried the first name, surname, rank or grade, gender and posting location of all 9,483 PSNI officers and civilian staff — the entire workforce, in a jurisdiction where officers routinely conceal their employment for their own safety. It was online for roughly two to three hours. Two days later the chief constable said dissident republicans claimed to have copies in circulation. The ICO later fined the force £750,000, reduced from an initial assessment of around £5.6 million, and called it the most significant data breach in the history of UK policing. No attacker was involved at any point. It belongs in this archive precisely because it is so often miscategorised as a hack.

Also that month · Two years inside

The UK Electoral Commission's very late notice

On the same day as the PSNI leak, the Electoral Commission disclosed that hostile actors had been inside its email and file-sharing systems since August 2021 — an intrusion it did not detect until October 2022, and did not announce until August 2023. The material likely accessible included electoral registers holding the name and address of anyone registered to vote in the UK between 2014 and 2022, reported as up to roughly 40 million people. The Commission said it could not determine whether the data had actually been copied. In March 2024 the UK government attributed the compromise to a Chinese state-affiliated actor, and the ICO later reprimanded the Commission over unpatched servers and weak passwords. Two years inside, ten months to disclose.

India desk · August 2023

India's first data protection law, passed in four days

The Lok Sabha passed the Digital Personal Data Protection Bill on 7 August 2023 and the Rajya Sabha on 9 August, both amid opposition protests and with minimal floor debate. President Droupadi Murmu granted assent on 11 August, making the DPDP Act, 2023 India's first comprehensive personal data protection law — six years after the Supreme Court's Puttaswamy judgment recognised privacy as a fundamental right, and a year after the government withdrew its earlier bill. The Act provides for penalties up to ₹250 crore per instance where a data fiduciary fails to take reasonable security safeguards, enforced by a Data Protection Board yet to be constituted.

And then nothing happened. The Act's provisions were left to be notified separately, and the operative rules followed only much later — draft rules in January 2025, notification in November 2025. August 2023 marked passage, not protection. As readers of this archive's later editions know, Indian citizens spent the intervening two years having their data lost — Star Health, ICMR, BSNL, boAt, Hathway — under a law that existed on paper and could not yet be enforced.

⏳ Time capsule — August 2023

  • Wind-driven wildfires destroyed the historic town of Lahaina on Maui on 8 August — the deadliest US wildfire in more than a century.
  • Spain beat England 1–0 in Sydney on 20 August to win the FIFA Women's World Cup for the first time.
  • India's Chandrayaan-3 lander touched down near the Moon's south pole on 23 August, the first mission ever to reach that region.
  • A business jet crashed in Russia's Tver region on 23 August, killing all ten aboard including Wagner chief Yevgeny Prigozhin.
Where it stands today — 2026

The call that became a lawsuit

Clorox v. Cognizant, filed in July 2025 and covered in this archive's own July 2025 edition, turned a help-desk password reset into a $380 million legal question — and with it, the industry's assumption that outsourced support is a cost centre rather than a security control. Identity-verification requirements for service desks are now standard contract language, precisely because of months like this one. The PSNI breach, meanwhile, remains the definitive reminder that the most damaging data loss can involve no adversary at all, only a spreadsheet tab nobody checked. And India's four-day passage of the DPDP Act began a two-year gap between having a law and having protection — the gap this magazine's India edition was created to cover.