
Hexaware Technologies Ltd has concluded its internal investigation into reports of a potential data breach and found no evidence of compromise. According to a stock exchange filing, the company stated there is no reliable evidence of breach of its systems or customer environments. The investigation revealed that the information referenced in the reports appears to be outdated and does not contain any sensitive information. As reported by CNBC TV18, the company emphasized that no critical systems of the company nor the data of customers have been compromised. The company's denial comes amid a larger cybersecurity incident affecting multiple major organizations, with the claimed total now sitting above 3.64 million records across nine organizations.
The IT services provider has implemented multiple layers of security controls across its systems and places importance on system security, data privacy and customer trust. According to the company's statement, Hexaware Technologies is treating the reported matter seriously and is currently assessing and verifying the details of the claim. The company added that appropriate actions will be taken wherever required to address any potential concerns. Despite the company's denial of any breach, shares of Hexaware Technologies Ltd ended at ₹549.90, down by ₹3.40, or 0.61% on the BSE, reflecting broader market concerns about the larger Azure breach affecting multiple major firms.
The company's denial comes amid a larger cybersecurity incident affecting multiple major organizations. A threat actor using the alias 'TheHatman' has been listing employee data allegedly stolen from Microsoft Azure and Entra ID tenants, with the claimed total now sitting above 3.64 million records across nine organizations. According to recent reports, the affected companies include McDonald's (over 1.7 million records), Tata Consultancy Services (800,000 records), Vodafone (425,000 records), HCL Technologies (250,000 records), InterContinental Hotels Group (185,000 records), Kyndryl (170,000 records), Gap (80,000 records), Hexaware (20,000 records), and Wyndham Hotels (9,000 records). The data includes directory-style information such as names, corporate email addresses, job titles, phone numbers, employee IDs, and in some cases, service-account and privileged-account details. The attacker began posting details on 1 August, claiming to have downloaded the information from company Azure tenants using compromised credentials.
Security experts have raised significant concerns about the breach's implications, particularly regarding the exposure of service accounts and global admin credentials. Hudson Rock, a threat intelligence firm, noted that "the exposure of service accounts and global admin names is particularly concerning, as this provides a direct road map for subsequent social engineering, spear-phishing or targeted privilege escalation attacks against these organizations." The leaked directories include employee IDs, job titles, departments, managers and direct reports, group memberships and service accounts, with some records allegedly identifying accounts with Global Administrator privileges. John Fitzpatrick from Lab539 emphasized that "the data includes phone numbers, which is a concern given how data-extortion groups such as Scattered Spider have used phone numbers to target help desk employees and trick them into granting direct access to corporate systems." The data appears to have come from victim organizations' Microsoft Entra portals, with many listings being cross-posted between DarkForum, PwnForums and BreachForums.
Multiple affected organizations have provided detailed responses to the breach claims. Tata Consultancy Services stated that "the information referenced appears to be more than four years old and limited to basic employee information" and found no signs of system compromise. HCLTech confirmed the breach was "limited and dated to a few years back" and continues to probe the incident. Vodafone assessed that "the data is old Vodafone employee information that would be available on a business card" with no customer data impact identified. TCS told investors that the attacker had claimed to use password spraying and repeated multi-factor authentication requests as an entry point, but said safeguards against those techniques had been in place for more than two years and remained effective. Despite the company's denial of any breach, shares of Hexaware Technologies Ltd ended at ₹549.90, down by ₹3.40, or 0.61% on the BSE, reflecting broader market concerns about the larger Azure breach affecting multiple major firms.