TCS finds no credible evidence of system breach after employee data exposure claims
Synopsis
Key Takeaways
Tata Consultancy Services (TCS), India's largest IT services company, on Monday, 10 August stated it has found no credible evidence of a breach of its systems or customer environments, following threat-intelligence alerts alleging the possible exposure of certain employee information. The company disclosed the development through a formal stock exchange filing.
What the Alerts Claimed
The threat-intelligence alerts alleged that certain employee data belonging to TCS may have been exposed. According to the company's own assessment, the information referenced in the claims appeared to be more than four years old and was limited to basic employee details. TCS confirmed there is no indication that customer data, customer systems, or TCS operational systems have been impacted.
Alleged Attack Vectors
The attacker reportedly claimed to have used password spraying and Multi-Factor Authentication (MFA) fatigue as the alleged attack vectors. TCS said it has had strong safeguards against both techniques in place for more than two years and that, based on its current review, these controls remain effective.
What TCS Said
'This is to inform you that the company has received threat-intelligence alerts alleging possible exposure of certain employee information. The company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,' the company stated in its filing.
It added: 'The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.'
On its security posture, TCS noted: 'The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.'
Ongoing Monitoring and Next Steps
TCS said it continues to closely monitor its environment and will evaluate any new information that may emerge, taking appropriate action if required. This comes amid a broader global surge in cyber threats targeting large enterprises through credential-based attacks — a pattern that has grown increasingly common across the IT services sector. Notably, MFA fatigue attacks, where attackers bombard users with authentication requests to induce accidental approval, have been flagged by cybersecurity agencies worldwide as a rising threat vector.