TCS Reports Possible Exposure Of Employee Data
Tata Consultancy Services (TCS) has received threat-intelligence alerts alleging possible exposure of certain employee-related information.
The IT services major, however, said its investigation has found no credible evidence of a breach of TCS systems or customer environments.
TCS said the information referenced in the alerts appears to be more than four years old and is limited to basic employee information.

Customer Data Not Impacted
TCS has specifically clarified that there is no indication that customer data, customer systems or its own operational systems have been affected.
The clarification is significant because the company works with major businesses globally and handles large volumes of sensitive corporate and technology information.
According to TCS, its current assessment does not point to any compromise of customer environments.
Attackers Allegedly Used Password Spraying And MFA Fatigue
The threat intelligence referenced claims that attackers used password spraying and multi-factor authentication (MFA) fatigue as the possible attack methods.
Password spraying involves attempting commonly used passwords across multiple accounts rather than repeatedly targeting a single account.
MFA fatigue attacks, meanwhile, attempt to overwhelm users with repeated authentication requests in the hope that someone eventually approves one.
TCS said it has had safeguards against these types of attacks in place for more than two years.
TCS Says Its Security Controls Remain Effective
Following its review, TCS said its existing security controls remain effective.
The company is continuing to monitor its environment and assess any additional information that becomes available.
TCS has also said it will take appropriate action if the ongoing assessment identifies anything requiring further intervention.
The company has not confirmed the exact source of the data referenced in the alerts.
Basic Employee Information Allegedly Involved
The information described by TCS is understood to be limited to basic employee-related details and appears to be more than four years old.
Reports circulating online had alleged that employee information was being offered through a hacking forum.
The claims included details such as employee names, identification numbers, email addresses, job titles, phone numbers and addresses.
TCS has not confirmed the authenticity or origin of all the information mentioned in those claims.
No Evidence Of A Current Systems Breach
TCS’s statement carefully distinguishes between an allegation of employee data exposure and an actual breach of its current systems.
The company has said it has not found credible evidence of a breach involving its systems or customer environments.
It has also stressed that there is no indication of an impact on customer data or operational systems.
The investigation and monitoring therefore remain ongoing rather than being treated as confirmation of a successful cyberattack.
Cybersecurity Risks Continue To Evolve
The incident highlights the growing cybersecurity challenges faced by large technology companies.
Attack techniques such as password spraying and MFA fatigue continue to be used against organisations, making identity protection and authentication security increasingly important.
For companies managing large employee populations and extensive technology infrastructure, preventing compromised credentials from being used to access systems remains a critical security priority.
TCS says its existing safeguards against the alleged attack methods remain effective and that it will continue monitoring its environment.
Summary
TCS has received threat-intelligence alerts alleging possible exposure of certain employee-related information but says it has found no credible evidence of a breach of its systems or customer environments. The information appears to be more than four years old and limited to basic employee data. TCS said there is no indication that customer data, customer systems or operational systems were affected and that its safeguards against password spraying and MFA fatigue remain effective.
