Editorial draft v1 · Evidence reader R3 · Evidence cutoff: August 8, 2024
Disclosures covered: August 14 and October 4, 2023 disclosures, followed by the fiscal-2024 annual report and financial statements filed August 8, 2024.
Clorox's August 2023 cyberattack disrupted order processing and product availability, with consequences for sales and earnings. Its selected disclosures move from an early investigation and operational workarounds to a preliminary quarterly forecast, then a fiscal-year account of normalized operations and costs partly offset by recognized insurance recoveries. The financial figures describe different periods and treatments; they are not successive estimates of one interchangeable loss total. Initial filing · October update · Annual report · Financial statements
From offline systems to automated ordering
On August 14, Clorox disclosed unauthorized activity on some IT systems. It took certain systems offline, coordinated with law enforcement, and engaged outside cybersecurity experts. Business-continuity workarounds allowed some customer service to continue, but disruption was already occurring. The later annual report added that the activity began on August 11 and that the company became aware of it that evening. It described manual ordering and processing at reduced operating levels, widespread disruption through the rest of the first fiscal quarter, and interim controls to maintain financial-reporting controls while systems were offline. Initial filing · Annual report
The October 4 update said Clorox believed the attack had been contained. It had started transitioning back to automated order processing on September 25, and the vast majority of orders were again automated. That allowed output and shipments to increase as the company rebuilt retailer inventories. Restocking was expected to take time, and Clorox anticipated continuing, though lessening, operational effects in its second quarter. Its assessment of the fiscal-year impact remained under way. October update
The annual account described order delays and significant product outages that had reduced net sales and earnings. It said Clorox had returned to normalized operations after lessening impacts in the second quarter. This later restoration statement advances the earlier recovery forecast; it does not change the fact that disruption had occurred. Annual report · Financial statements
Reading the financial measures
For the first quarter of fiscal 2024, ended September 30, 2023, the October release forecast a year-over-year net-sales decrease of 23%–28% and an organic-sales decrease of 21%–26%. It projected a diluted loss per share of $0.35–$0.75 and an adjusted result ranging from a $0.40 loss per share to zero. Those were preliminary forecasts, subject to incomplete closing procedures—not final results or dollar amounts of incident costs. October update
The sources express the following cost amounts in millions of dollars. The $19 million after-tax amount is the tax-adjusted counterpart of the preliminary $25 million figure, rather than an additional expense. The later annual net-cost measure and recognized insurance amount have their own scopes. October update · Financial statements
| Disclosure | Measure | Qualification |
|---|---|---|
| October 4, 2023 preliminary account | Approximately $25 million in attack-related costs for the three months ended September 30; $19 million after tax | Excludes potential insurance recoveries; not a final quarterly result |
| Fiscal-2024 annual account | Approximately $29 million in incremental costs for fiscal 2024 | Net of insurance recoveries |
| Fiscal-2024 fourth quarter | $30 million in insurance recoveries recognized | Accounting recognition; the selected passage does not establish cash receipt |
The attack-related costs principally concerned investigation and remediation services, including forensic, legal, and IT specialists, plus incremental operating costs caused by the disruption. The October adjustment excluded ongoing monitoring, prevention, and cybersecurity-program enhancement costs, and the company then expected further attack-related costs. The later financial statements said significant future attack-related costs were not expected. Both disclosures cautioned that the timing of insurance recognition could differ from the timing of associated expenses. October update · Financial statements
What the later account adds—and what it does not
The annual report supplies a retrospectively stated activity-onset date, a stronger restoration account, and fiscal-year accounting that the initial filing could not provide. Editorial interpretation: keeping those stages separate makes the operational and financial progression readable without treating a preliminary forecast as a final outcome. The selected sources do not establish a named attacker, a data-theft population, or a root cause. That limited coverage is not a finding that no data was affected. Initial filing · October update · Annual report · Financial statements
Sources
Initial filing — August 14, 2023.
Preliminary update — October 4, 2023; first fiscal quarter ended September 30.
Annual report and financial statements — August 8, 2024; fiscal year ended June 30.