People Matters Logo

TCS denies system breach after employee data exposure claim

• By Ria Duneja
TCS denies system breach after employee data exposure claim

Tata Consultancy Services (TCS) has received alerts about the possible exposure of employee data. The IT services major said it found no credible evidence of a breach.


Reuters reported the development after TCS disclosed the alerts on Monday.


The company said the data appears to be more than four years old. It is also limited to basic employee information.


Customer data remains unaffected


TCS said there is no evidence that customer data was affected.


It also said its customer systems and operational systems remain secure.


“The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted. The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector,” TCS said in an exchange filing.


The disclosure came after an August 10 post on X by @S2W_DailyThreat.


The post claimed that TCS employee data was being sold on the darknet.


It alleged that the data came from an Azure dump linked to a threat actor known as “TheHatman”.


The post claimed the data included names, employee IDs, email addresses, job titles, phone numbers and addresses.


It also claimed that a 6,000-record sample was included in the listing.


TCS finds no credible breach


TCS said it reviewed the claims. The review found no evidence of a breach.


“The firm said it had examined the claims and had “not found any credible evidence of a breach of TCS systems or customer environments.”


The company said it has had safeguards against the alleged attack methods for more than two years.


“Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely. The Company will continue to assess any new information that becomes available and take appropriate action, if required,” TCS said.


TCS said it will continue to monitor its systems.


It also pledged to protect company and customer information.


“The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.”


Focus on cybersecurity


The claims highlight the growing risks facing large companies.


Password spraying and MFA fatigue are common techniques used in cyberattacks.


TCS said its safeguards against these methods remain effective.


The company will continue to assess any new information. It said it will take action if required.


For now, TCS maintains that there is no evidence of a breach affecting its systems or customers.