
Both Tata Consultancy Services (TCS) and HCLTech have issued official denials following threat-intelligence alerts alleging potential data breaches. According to a stock exchange filing by TCS on Monday (August 10), the company has found no credible evidence of a breach of its systems or customer environments after receiving threat-intelligence alerts alleging possible exposure of certain employee information. The IT services giant stated that it has investigated the matter thoroughly and determined that no breach occurred. In an exchange filing late Monday night, HCLTech confirmed that its initial investigation has revealed that the data may be limited and dated to a few years back, with no evidence of breach to the company's systems or engagement with any of the company's clients. The company emphasized that it is undertaking further investigation, and any material findings in this regard will be reported. As reported by Business Standard, HCLTech further stated that it considers cyber security as its top priority and remains committed to protecting the information entrusted to it.
As reported by S2W, the alleged dataset includes employee names, IDs, email addresses, job titles, phone numbers, and addresses. The threat actor attached a sample of about 6,000 records and is offering the database at a price to be negotiated. However, the claims raise significant questions about their validity. The alleged database is larger than TCS' current workforce of approximately 5.9 lakh employees, creating a substantial discrepancy. The claims also suggest that the data was extracted from TCS' Azure environment using compromised credentials, though this methodology has not been independently verified. S2W noted that the claims of accessing an Azure tenant using compromised credentials could point to access brokering and resale of stolen data. As reported by Business Standard, both companies have confirmed that the data referenced in the alerts appears to be more than four years old and is limited to basic employee information.
Both companies have confirmed that the data referenced in the alerts appears to be more than four years old and is limited to basic employee information. TCS emphasized that there is no indication that customer data, customer systems, or TCS operational systems have been impacted. HCLTech noted that the data may be limited and dated to a few years back, significantly reducing the current relevance of the claims. Both companies confirmed that safeguards against such attacks have been in place for more than two years, demonstrating their proactive approach to cybersecurity. The companies have not disclosed the nature or volume of the data allegedly exposed, nor confirmed whether the information was obtained directly from their systems or through another source. As reported by Business Standard, both companies received similar claims from a hacker group regarding potential exposure of limited data elements related to their employees.
According to the company statements, the attackers claim to have used password spraying and Multi-Factor Authentication (MFA) fatigue as attack vectors. TCS maintains that it has had safeguards against such techniques in place for more than two years and, based on its current review, these controls remain effective. HCLTech stated that it considers cyber security as its top priority and remains committed to protecting the information entrusted to it. Both companies stated that they continue to monitor their environment closely and will assess any new information that becomes available and take appropriate action if required. The investigation remains ongoing for HCLTech, as the company has not confirmed a systems breach or any impact on client environments as of its latest exchange filing.
TCS shares closed 0.80% down at ₹2,434 on the BSE on Monday, against gains of 0.06% in the benchmark, reflecting investor concerns about the cybersecurity incident despite the company's official denial. The stock opened at ₹2,452.70 and touched an intraday high of ₹2,472.90 before settling at the current level. The market reaction suggests broader sensitivity to cybersecurity developments, particularly for IT services companies. At Monday's closing price, the stock remains well below its 52-week high of ₹3,350, indicating continued pressure throughout 2026. The company maintains a market capitalization of approximately ₹8.81 lakh crore with a price-to-earnings ratio of 17.67.