started · updated
Tata Consultancy Services denies system breach following employee data claims
Tata Consultancy Services (TCS) has stated that its investigation found no credible evidence of a breach involving its systems or customer environments following threat-intelligence alerts. The company addressed claims that employee-related data had been exposed.
The alerts followed a social media post by @S2W_DailyThreat, which alleged that a threat actor known as “TheHatman” was offering TCS employee data for sale on the darknet via an Azure dump. The claims suggested the data included names, employee IDs, email addresses, job titles, phone numbers, and addresses, accompanied by a 6,000-record sample.
TCS clarified in a regulatory filing that the information referenced in the alerts appears to be more than four years old and is limited to basic employee information. The company emphasized that there is no indication that customer data, customer systems, or TCS operational systems have been impacted.
The attacker allegedly claimed to have used password spraying and Multi-Factor Authentication (MFA) fatigue as attack vectors. TCS stated it has maintained effective safeguards against these specific techniques for over two years and continues to monitor its environment closely.