HCLTech finds no systems breach after hacker group claims employee data leak

Share:
Audio Loading voice…
HCLTech finds no systems breach after hacker group claims employee data leak

Synopsis

Two of India's biggest IT exporters — HCLTech and TCS — have been hit by hacker group claims of employee data exposure within days of each other. Both say investigations found no system breach and the data appears old, but the pattern of coordinated claims against sector giants using MFA fatigue tactics signals a broader threat campaign worth watching.

Key Takeaways

HCLTech disclosed on 11 August that its initial investigation found no evidence of a breach following hacker group claims of employee data exposure.
The company said any exposed data appears 'limited and dated to a few years back.' Peer Tata Consultancy Services (TCS) issued a similar clarification earlier this week, saying referenced data was more than four years old.
TCS noted the alleged attacker claimed to use password spraying and MFA fatigue as attack vectors.
HCLTech shares were trading higher at ₹1,371 on the BSE at the time of the filing.
Both companies say investigations are ongoing and material findings, if any, will be disclosed.

HCLTech, one of India's largest IT services companies, said on 11 August that its initial investigation found no evidence of a breach of its systems or any impact on client engagements, following claims by a hacker group alleging the potential exposure of employee-related data. The company made the disclosure through a stock exchange filing, responding to media reports that cited the hacker group's allegations.

What HCLTech's Investigation Found

In its filing, HCLTech stated that any data potentially referenced by the hacker group appears to be 'limited and dated to a few years back.' The company confirmed there was no evidence of a breach at its systems and no engagement with any of its clients had been affected.

HCLTech added that it is continuing to investigate the matter and will disclose any material findings arising from the review. 'The company considers cyber security as its top priority and remains committed to protecting the information entrusted to it,' the firm said in its filing.

A Sector-Wide Pattern: TCS Faced Similar Claims

The HCLTech disclosure follows a near-identical situation at peer Tata Consultancy Services (TCS), which issued a comparable clarification earlier this week after threat-intelligence alerts alleged possible exposure of certain employee information. On Monday, TCS told stock exchanges it found no credible evidence of a breach of its systems or customer environments.

According to TCS, the information referenced in the alerts appeared to be more than four years old and was limited to basic employee details. TCS also confirmed there was no indication that customer data, customer systems, or TCS operational systems had been impacted. Notably, TCS noted in its filing that the alleged attacker claimed to have used password spraying and multi-factor authentication (MFA) fatigue as attack vectors — techniques that exploit human behaviour rather than technical vulnerabilities.

Market Reaction

Shares of HCLTech were trading higher at ₹1,371 per share on the BSE at the time of the disclosure, suggesting investors were not significantly rattled by the hacker group's claims.

Why This Matters for India's IT Sector

The near-simultaneous claims against two of India's top-tier IT exporters — HCLTech and TCS — raise questions about whether a coordinated threat campaign is targeting the sector. Both companies serve global clients across banking, healthcare, and government, making even unverified breach claims reputationally sensitive. This comes amid a broader global rise in social-engineering attacks, where MFA fatigue and credential-stuffing are increasingly preferred over direct system intrusions. Whether the data in question was obtained through a third-party vendor, a legacy system, or an internal exposure remains under investigation.

Point of View

A threat that no firewall alone can address. Both companies have been careful to say 'no evidence of breach' rather than 'no breach' — a legally precise distinction that leaves room for further findings. India's IT sector, which manages sensitive data for Western banks, insurers, and governments, has long been a high-value target; the real question is whether these claims represent a genuine exfiltration or a reputational pressure campaign designed to extract a ransom or market reaction.
NationPress
11 Aug 2026

Frequently Asked Questions

What did HCLTech say about the hacker group's claims?
HCLTech said its initial investigation found no evidence of a breach of its systems or any impact on client engagements. The company added that any data potentially involved appears to be limited and dated to a few years back.
What attack methods did the hacker group allegedly use against TCS?
According to TCS's stock exchange filing, the alleged attacker claimed to have used password spraying and multi-factor authentication (MFA) fatigue as attack vectors. These techniques exploit user behaviour rather than direct technical vulnerabilities.
Was any customer data compromised at HCLTech or TCS?
Both companies said there was no evidence that customer data or client systems were impacted. TCS explicitly stated that customer data, customer systems, and TCS operational systems showed no signs of being affected.
Why did both HCLTech and TCS face similar claims around the same time?
The near-simultaneous claims against both firms have not been fully explained, and investigations are ongoing. Security analysts note a global rise in coordinated threat campaigns targeting large IT service providers, often using social-engineering techniques like MFA fatigue.
What happens next in the HCLTech investigation?
HCLTech has said it is continuing to investigate the matter and will disclose any material findings if they arise from the review. The company reiterated that cybersecurity is its top priority.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 15 hours ago
  2. 1 month ago
  3. 1 month ago
  4. 1 month ago
  5. 2 months ago
  6. 7 months ago
  7. 8 months ago
  8. 9 months ago
Google Prefer NP
On Google