TCS Dismisses Employee Data Exposure Claims, Citing No Breach and Outdated Information

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
Tata Consultancy Services (TCS) has pushed back against recent claims of a significant employee data exposure, stating its investigation found no credible evidence of a breach in its systems or customer environments. The denial comes after a threat intelligence alert from data security firm S2W on X, detailing a hacker named 'TheHatman' allegedly offering over 800,000 TCS employee records for sale on an underground cybercrime forum called BreachForums. The allegedly exposed data included full names, employee IDs, email addresses, job titles, phone numbers, and addresses. The claims suggested the data was extracted from TCS Azure environment using compromised credentials, employing techniques like password spraying and MFA fatigue. However, TCS highlighted that the information referenced in the alerts appears to be more than four years old and consists only of basic employee details. This raises questions, especially since the purported 800,000 records exceed TCS current workforce of approximately 590,000 employees. Importantly, the company reassured stakeholders that customer data, customer systems, or its operational systems were not impacted, and its safeguards against the alleged attack vectors have been effective for over two years. As TCS continues to monitor its environment closely, this incident underscores the growing cybersecurity pressures faced by major Indian IT service providers. Just hours after TCS announcement, HCLTech, another prominent Indian IT firm, also reported and denied similar claims of employee data exposure. While both companies maintain no breach occurred, these alerts serve as a stark reminder for organizations to remain vigilant against persistent cyber threats and for individuals to be cautious about their personal data in the digital realm.