
Several major Indian IT companies have downplayed data breach reports following a cyber intelligence firm's findings, but cybersecurity experts say the commercial damage may matter more than technical severity. According to Business Standard, TCS, HCLTech and Hexaware issued statements to the exchange that even if certain employee information may have been breached, the information was old and limited. However, cybersecurity expert Sunny Nehra from Secure Your Hacks noted that 'The hacks did take place, as the leaked material is consistent with genuine Azure or Entra exports. The access event is real even if the companies dispute its timing and depth'. The denials and statements came following a report by cyber intelligence firm Hudson Rock, which showed more than 800,000 records of TCS, 20,000 of Hexaware and 250,000 of HCLTech were allegedly exposed by threat actor 'TheHatman' who claimed to have sourced the companies' Azure tenants.
Experts argue that the technical severity of the breaches is less important than the commercial exposure they create. As reported by Business Standard, Srinivas L, joint MD and CEO of 63SATS Cybertech, explained that 'India runs a large part of the world's back office, and trust is the actual product we sell. One thing I would gently disagree with is the argument that the data is old. A password ages. But the organisation chart does not. A four-year-old reporting line is still a working map and a live target'. Sunny Nehra points to a legal dimension behind companies' emphasis on data age, noting that 'From a Digital Personal Data Protection (DPDP) Act perspective, this distinction becomes especially useful for the companies. Employee directory data is clearly personal data under the Act. By characterising the incident as an older event that occurred well before the relevant DPDP provisions became fully operative, the companies can argue that the strict new notification timelines and penalty exposure do not automatically apply'. The companies' reluctance to confirm breaches comes down to risk, reputation and liability management, as acknowledging a breach immediately invites questions from clients and can trigger contractual notice requirements, insurance notifications and regulatory scrutiny.
While acknowledging that no company is immune to attacks in the AI age, cybersecurity experts call for more prevention mechanisms rather than resilience. According to Business Standard, Ranjeeth Bellary, partner at EY's cyber forensics & incident response, explained that 'new-age attackers have moved on from ransomware to identity thefts and supply chains, thus increasing the impact radius. Bigger attacks always compromise humans than systems'. Pankit Desai, co-founder and CEO of Sequretek, noted that 'This is a people-dependent industry and with AI, it will get increasingly difficult to fight the new battle with old technology. You need vulnerability management, threat exposure management, threat detection, configuration management to run 24/7 and not in cycles as was the case earlier'. The shift demands a different posture from IT firms than the one they have relied on so far, requiring 24/7 threat detection and configuration management rather than traditional cyclical approaches.
Recent reports suggest that TCS has begun deploying a monitoring tool on employee laptops to track staff activity through company devices. As reported by Money Control, the software, described as a Digital User Experience Monitoring tool, has been installed on laptops provided to TCS employees. The tool reportedly can show which applications are being used and how much time is spent on them, providing the company with greater visibility into employee device usage. However, the company has not publicly explained the deployment or shared details about the software provider, categories of information being gathered, or which teams or officials can view the collected data. The scale of deployment across nearly 600,000 employees makes this development particularly significant and raises questions about where legitimate cybersecurity monitoring ends and workplace surveillance begins. According to Moneycontrol, EIIRTrend CEO Pareekh Jain explained that the intent is to understand whether applications are working properly and how much time is being spent on each application, emphasizing that employee monitoring data is important for managing infrastructure for clients but can also be used for surveillance.
TCS has denied reports that it is tracking individual employee activity through its Digital User Experience Monitoring tool, maintaining that its digital tools are intended to assess network performance and improve employee experience. As reported by India Today, the company stated that 'The reports regarding surveillance of employees are baseless and inaccurate. TCS does not track individual employee activity on laptops and respects their privacy'. The company clarified that its monitoring tools are used exclusively for 'macro-level network performance' to ensure security, availability and enhance digital experience for employees. However, the Moneycontrol report raised questions about whether the technology could provide employers with information about individual users, given its reported ability to identify applications accessed and time spent on them. Digital User Experience Monitoring systems are generally used by organisations to assess application, device and network performance, helping IT teams identify technical problems and improve system performance. Details about the specific system including its software provider, configuration, precise information collected and who within TCS can access it have not been publicly disclosed.