TCS Flags Possible Employee Data Exposure, Says Customer Data And Systems Safe


Mohul Ghosh

Mohul Ghosh

Aug 15, 2026


TCS Reports Possible Exposure Of Employee Data

Tata Consultancy Services (TCS) has received threat-intelligence alerts alleging possible exposure of certain employee-related information.

The IT services major, however, said its investigation has found no credible evidence of a breach of TCS systems or customer environments.

TCS said the information referenced in the alerts appears to be more than four years old and is limited to basic employee information.

TCS Flags Possible Employee Data Exposure, Says Customer Data And Systems Safe

Customer Data Not Impacted

TCS has specifically clarified that there is no indication that customer data, customer systems or its own operational systems have been affected.

The clarification is significant because the company works with major businesses globally and handles large volumes of sensitive corporate and technology information.

According to TCS, its current assessment does not point to any compromise of customer environments.

Attackers Allegedly Used Password Spraying And MFA Fatigue

The threat intelligence referenced claims that attackers used password spraying and multi-factor authentication (MFA) fatigue as the possible attack methods.

Password spraying involves attempting commonly used passwords across multiple accounts rather than repeatedly targeting a single account.

MFA fatigue attacks, meanwhile, attempt to overwhelm users with repeated authentication requests in the hope that someone eventually approves one.

TCS said it has had safeguards against these types of attacks in place for more than two years.

TCS Says Its Security Controls Remain Effective

Following its review, TCS said its existing security controls remain effective.

The company is continuing to monitor its environment and assess any additional information that becomes available.

TCS has also said it will take appropriate action if the ongoing assessment identifies anything requiring further intervention.

The company has not confirmed the exact source of the data referenced in the alerts.

Basic Employee Information Allegedly Involved

The information described by TCS is understood to be limited to basic employee-related details and appears to be more than four years old.

Reports circulating online had alleged that employee information was being offered through a hacking forum.

The claims included details such as employee names, identification numbers, email addresses, job titles, phone numbers and addresses.

TCS has not confirmed the authenticity or origin of all the information mentioned in those claims.

No Evidence Of A Current Systems Breach

TCS’s statement carefully distinguishes between an allegation of employee data exposure and an actual breach of its current systems.

The company has said it has not found credible evidence of a breach involving its systems or customer environments.

It has also stressed that there is no indication of an impact on customer data or operational systems.

The investigation and monitoring therefore remain ongoing rather than being treated as confirmation of a successful cyberattack.

Cybersecurity Risks Continue To Evolve

The incident highlights the growing cybersecurity challenges faced by large technology companies.

Attack techniques such as password spraying and MFA fatigue continue to be used against organisations, making identity protection and authentication security increasingly important.

For companies managing large employee populations and extensive technology infrastructure, preventing compromised credentials from being used to access systems remains a critical security priority.

TCS says its existing safeguards against the alleged attack methods remain effective and that it will continue monitoring its environment.

Summary

TCS has received threat-intelligence alerts alleging possible exposure of certain employee-related information but says it has found no credible evidence of a breach of its systems or customer environments. The information appears to be more than four years old and limited to basic employee data. TCS said there is no indication that customer data, customer systems or operational systems were affected and that its safeguards against password spraying and MFA fatigue remain effective.


Mohul Ghosh
Mohul Ghosh
  • 6294 Posts

Subscribe Now!

Get latest news and views related to startups, tech and business

You Might Also Like

Recent Posts

Related Videos

   

Subscribe Now!

Get latest news and views related to startups, tech and business

who's online