Connect with us

BUSINESS

TCS Employee Data Claim Leaves Old Dumps Still Dangerous

TCS and HCLTech deny fresh breaches of employee data offered by TheHatman, yet the multi-year-old dumps keep phishing and access-broker risks alive for Indian IT.

Published

on

TCS told stock exchanges on Monday it found no credible evidence of a breach after threat alerts claimed more than 800,000 employee records were for sale. The alleged dump is basic contact data more than four years old, the company said, with no impact on customer systems.

The same day brought a parallel denial from HCLTech. Together the episodes leave a sharper problem intact: old employee files still circulate on underground forums and still feed phishing and access brokering across Indian IT.

Alerts Reach the Exchanges

Data security firm S2W posted on X early Monday that a threat actor called TheHatman had listed a TCS employee Azure dump on Breachforums_V10. The post said the package held over 800,000 records of names, employee IDs, emails, job titles, phone numbers and addresses, with a 6,000-row sample attached and price left open to negotiation.

The seller claimed the data came straight from a TCS Azure tenant via compromised credentials. S2W noted the pattern pointed to access brokering and resale of stolen data. Claims remain unverified.

The company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.

That language came from TCS’s exchange filing, which also said the attacker claimed password spraying and multi-factor authentication fatigue as the vectors. The firm added it has held strong safeguards against those techniques for more than two years and that the controls remain effective while monitoring continues.

Why the Headcount Math Looks Off

TCS currently employs roughly 5.9 lakh people. An 800,000-record set therefore exceeds the live workforce. One ready explanation is inclusion of former employees, contractors or service accounts accumulated over years. Another is simple inflation of the listing.

Metric Claimed by TheHatman TCS Reported
Records / headcount 800,000+ 584,519 employees as of March 2026
Data age Not stated More than four years old
Fields listed Names, IDs, emails, titles, phones, addresses Basic employee information only
Sample size ~6,000 rows Not applicable

The official 584K+ global workforce figure on TCS’s own site aligns with the March 2026 tally and the earlier “about 5.9 lakh” figure used in coverage. Either way the mismatch undercuts any claim of a fresh full-tenant exfiltration of current staff.

Password Spray, MFA Fatigue and the Two-Year Shield

TCS stated the attacker claimed two classic credential techniques. Password spraying tests common passwords across many accounts. MFA fatigue bombards a user with push notifications until one is accepted by habit or error.

  • Password spraying against Azure identities
  • MFA fatigue / push bombing
  • Claimed direct dump of the Azure tenant
  • Offer of additional corporate dumps on request

The company said safeguards against exactly those methods have been in place more than two years. Its review found the controls still effective. That timeline places any successful use of the techniques well before the current hardening window, consistent with the four-plus-year age of the data itself.

HCLTech Files the Same Day

Hours after the TCS disclosure, HCLTech told exchanges it too had seen claims of employee data exposure. Its initial probe found the data “may be limited and dated to a few years back.” There was “no evidence of breach to the company’s systems or engagement with any of the company’s clients.” Further investigation continues and material findings will be reported.

The parallel language is striking. Two of India’s largest IT services firms, same 24-hour window, same conclusion of dated limited employee data and no live system or client impact. TheHatman had earlier listed a Hexaware Azure/Entra dump in the same style, per S2W. A single actor or method appears to be working the Indian IT bench.

That pattern sits alongside broader sector moves such as the India IT services AI investment bets by TCS, Infosys and Wipro. Security hygiene remains the quiet prerequisite for those technology shifts.

The 2025 Client Incidents Still Shadow the Sector

TCS has already spent months answering questions about cybersecurity incidents at clients. Jaguar Land Rover suffered a major attack beginning late August 2025 that halted production for weeks and drew estimates of nearly £1.9 billion in wider economic damage. Marks & Spencer and the Co-op faced related disruptions earlier that year. UK MPs wrote to TCS leadership seeking answers on possible links. TCS investigated and stated no TCS systems or users were compromised and no other customers were impacted. Some reporting noted M&S later adjusted its relationship with the firm.

  1. March 2025, Earlier Jira-related activity reported against JLR by groups such as HellCat.
  2. April-mid 2025, M&S and Co-op disruptions linked in public discussion to the same threat clusters.
  3. 31 August-September 2025, JLR production stoppage after confirmed cyber incident; parliamentary scrutiny of outsourcers follows.
  4. 10-11 August 2026, Fresh employee-data sale claims against TCS then HCLTech; both deny live breaches.

The new listings do not revive those client breaches. They do keep the supply-chain trust conversation alive. Large Indian IT providers sit inside the security perimeter of global manufacturers and retailers. Even a clean bill on current systems leaves residual questions about credential hygiene and data lifecycle years earlier.

What Circulating Old Records Still Enable

A four-year-old employee list is not a live network key. It remains useful raw material. Names, titles, emails, phone numbers and addresses support highly targeted phishing, business-email compromise and social-engineering of help desks. Service-account entries, if present, raise the stakes further.

S2W’s own note on the S2W threat post on TheHatman listing flagged the access-brokering angle: compromised credentials used to dump a tenant, then more corporate dumps advertised on request. That model treats access itself as inventory. Even when the original tenant has rotated credentials and hardened MFA, the sold contact data continues to travel.

Crowd reaction on X stayed measured. Most posts treated the claim as unverified and urged employees to ignore unofficial “TCS leak” notices that could themselves be phishing. The practical advice matches the residual risk: old directories become the bait for new compromises.

TCS and HCLTech have closed the immediate exchange-disclosure loop. The dumps, if authentic at any level, do not disappear with the filings. They sit on forums, change hands, and keep the second-order exposure alive for the sector that builds and runs so much of the world’s corporate IT.

Harrie Wade is a seasoned journalist with over 20 years of hands-on experience at leading U.S. news agencies, including CNN and Reuters, where he reported on diverse niches from politics and technology to environment and society. With specialized authority in YMYL topics like finance, health, and public safety, backed by collaborations with experts from the CDC, Federal Reserve, and peer-reviewed sources, he ensures evidence-based, accurate insights. Holding a Bachelor's in Journalism from Columbia University, Harrie founded News Analysis in 2015 to deliver original, unbiased content across all beats, while mentoring emerging journalists to uphold the highest ethical standards for trustworthy reporting.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending