Cognizant data breach 2026: Customers warned of personal data exposure after April attack

Share:
Audio Loading voice…
Cognizant data breach 2026: Customers warned of personal data exposure after April attack

Synopsis

Cognizant has disclosed a data breach dating back to 21 April 2026, potentially exposing Social Security numbers and personal data. With cybercrime group CoinbaseCartel reportedly claiming responsibility and peers TCS, HCLTech, and Hexaware all denying separate leak allegations in the same fortnight, India's IT sector is facing its sharpest cybersecurity scrutiny in years.

Key Takeaways

Cognizant notified customers of a data breach that occurred on 21 April 2026 , potentially exposing Social Security numbers and personal information.
The company says there is currently no evidence that the exposed data has been misused.
Cybercrime group CoinbaseCartel has reportedly claimed responsibility for the breach, according to media reports.
Affected customers are being offered 24 months of credit and CyberScan monitoring through identity protection firm IDX , plus up to $1 million in insurance reimbursement.
Cognizant has not disclosed the number of individuals affected by the incident.
Peers TCS , HCLTech , and Hexaware have separately denied reports of data leaks within their organisations over the past two weeks.

Cognizant Technology Solutions, one of the largest US-headquartered IT services firms with significant operations in India, has notified customers of a data breach that took place on 21 April 2026, potentially exposing personal information including Social Security numbers. The company stated it has found no evidence so far that the compromised data has been misused.

What Cognizant Disclosed

In a formal notification letter sent to affected individuals, Cognizant said it was issuing the alert as a precautionary measure. 'While we have no reason to believe that your information was misused, we thought it prudent to make this notification,' the company said. 'We deeply regret this incident and any inconvenience to you.'

Notably, Cognizant did not disclose the number of individuals affected by the breach, leaving the full scale of the incident unclear.

Who Is Claiming Responsibility

According to media reports, a cybercrime group identified as CoinbaseCartel has reportedly claimed responsibility for the attack. The group allegedly accessed systems that held sensitive personal data, though independent verification of this claim remains pending.

Protections Offered to Affected Individuals

Cognizant has advised those affected to consider filing a police report or placing a security freeze on their credit reports at no cost. A security freeze prevents credit reporting agencies from sharing a consumer's credit file without explicit written authorisation.

The company has additionally enrolled affected customers in identity theft protection services through IDX, a specialist data breach response provider. The package covers 24 months of credit and CyberScan monitoring, identity theft recovery support, and an insurance reimbursement policy of up to $1 million. 'With this protection, IDX will help you resolve issues if your identity is compromised,' Cognizant said in its notification.

Broader Scrutiny of Indian IT Sector

The disclosure arrives amid heightened scrutiny of cybersecurity practices across India's IT services industry. Over the past two weeks, peers including Tata Consultancy Services (TCS), HCLTech, and Hexaware have each denied separate reports of alleged employee data leaks within their organisations. This is the latest in a string of incidents that has put the sector's data security posture under a spotlight.

As investigations continue, affected customers are being urged to monitor their financial accounts closely and make use of the protective services Cognizant has arranged.

Point of View

How the attackers gained access, or whether the breach has been fully contained. The 21 April breach date against a late-August notification also raises questions about the timeline of internal discovery and regulatory reporting. More broadly, the cluster of alleged data incidents across TCS, HCLTech, and Hexaware in the same fortnight — even if individually denied — signals that threat actors are actively targeting Indian IT supply chains, which hold sensitive data for millions of global clients. The sector's self-regulatory posture on disclosure has historically lagged Western peers; this incident may accelerate regulatory pressure for mandatory breach timelines in India.
NationPress
21 Aug 2026

Frequently Asked Questions

What happened in the Cognizant data breach of 2026?
Cognizant suffered a data breach on 21 April 2026 that may have exposed customers' personal information, including Social Security numbers. The company has notified affected individuals as a precautionary measure, stating it has found no evidence of misuse so far.
Who is responsible for the Cognizant cyberattack?
According to media reports, a cybercrime group known as CoinbaseCartel has reportedly claimed responsibility for the breach. This claim has not been independently verified, and Cognizant has not publicly confirmed the identity of the attackers.
What protections is Cognizant offering to affected customers?
Cognizant is providing 24 months of credit and CyberScan monitoring through IDX, along with identity theft recovery support and an insurance reimbursement policy of up to $1 million. Customers have also been advised to place a free security freeze on their credit reports.
How many people were affected by the Cognizant data breach?
Cognizant has not disclosed the number of individuals affected by the breach. The full scale of the incident remains unknown as of the notification date.
How does this breach fit into the broader Indian IT sector picture?
The Cognizant disclosure comes amid a two-week period in which peers TCS, HCLTech, and Hexaware have each denied separate reports of alleged employee data leaks. It reflects growing scrutiny of cybersecurity practices across India's IT services industry, which manages sensitive data for clients worldwide.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 week ago
  2. 1 week ago
  3. 2 weeks ago
  4. 3 months ago
  5. 3 months ago
  6. 8 months ago
  7. 11 months ago
  8. 1 year ago
Google Prefer NP
On Google