“No Credible Evidence of a Breach”: TCS on Data Claim

TCS told the BSE it found no credible evidence of a breach after alerts flagged possible employee data exposure it says is over four years old.
“No Credible Evidence of a Breach”: TCS on Data Claim
TPB Logo
Tuesday August 11, 2026
2 min Read

Share

Tata Consultancy Services (TCS) said on Monday it found no credible evidence that its systems or customer environments were breached, after threat-intelligence alerts flagged the possible exposure of some employee information. India’s largest IT services firm made the statement in a filing with the BSE on August 10, 2026.

The alerts pointed to employee data allegedly surfacing on a hacking forum. TCS said its investigation traced the referenced information to material that is more than four years old and limited to basic employee details.

“The company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” the company said in its exchange filing. It added that the referenced information “appears to be more than four years old and limited to basic employee information,” with no indication that customer data, customer systems, or operational systems were affected.

The claim that prompted the alerts had circulated on X, where posts said employee records including full names, IDs, job titles, phone numbers and addresses were listed on the hacking forum BreachForums. The person behind the claim said the data was pulled from TCS’s Azure tenant using compromised credentials, and cited password spraying and multi-factor authentication (MFA) fatigue as the methods used.

TCS pushed back on the technical claim directly. The company said it has kept safeguards against both password spraying and MFA fatigue in place for more than two years, and that those controls remain effective. “Based on the current review, these controls remain effective, and the company continues to monitor the environment closely,” it said.

The company has not named the source of the current threat-intelligence alerts, nor has it detailed which cohort of employees the four-year-old data covers. It said it would evaluate any new information as it emerges.

Author
//
The TPB Team
latest news

trending

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.

More of this topic

Subscribe To Our Newsletter

Never miss a story

By submitting your information, you will receive newsletters and promotional content and agree to our Terms of Use and Privacy Policy. You may unsubscribe at any time.