Tata Consultancy Services (TCS) told stock exchanges on Monday that it received threat-intelligence alerts alleging possible exposure of certain employee information, but its investigation found no credible evidence of a breach of its systems or customer environments, according to a report by Business-Today.
Threat alerts and stock exchange disclosure
Business-Today reported that the disclosure follows a post by data security firm S2W on the social platform X, in which S2W said a threat actor using the name "TheHatman" had allegedly offered more than 800,000 TCS employee records for sale on an underground cybercrime forum.
In its regulatory filing, TCS said the information referenced in the threat alerts appears to be more than four years old and limited to basic employee information. TCS also said it continues to closely monitor its environment and will assess any new information and take appropriate action if required, according to Business-Today.
Business-Today reported TCS's conclusion:
The investigation found no credible evidence of a breach of TCS's systems or customer environments.
The alleged dataset, by the numbers
S2W's post claimed the data was extracted from TCS's Azure environment using compromised credentials, Business-Today reported. The alleged dataset includes employee names, IDs, email addresses, job titles, phone numbers, and addresses. The threat actor attached a sample of about 6,000 records and is offering the database at a price to be negotiated, S2W said.
S2W also said the claims of accessing an Azure tenant using compromised credentials could point to access brokering and resale of stolen data. The claims have not been independently verified, according to Business-Today.
| Metric | Figure |
|---|---|
| Alleged employee records offered for sale | More than 800,000 |
| TCS current workforce | About 5.9 lakh (590,000) |
| Sample records attached by threat actor | About 6,000 |
| Age of data per TCS | More than four years old |
A database larger than the workforce
The size discrepancy is notable: the alleged database tops the company's entire current workforce of about 5.9 lakh employees, as Business-Today reported. TCS's exchange filing said the referenced information appears to be more than four years old and limited to basic employee information, a detail that frames the company's assessment of the alert.
Client cybersecurity scrutiny
The disclosure comes as TCS has faced scrutiny around cybersecurity incidents involving some of its clients, including Jaguar Land Rover (JLR) and Marks & Spencer (M&S), according to Business-Today.
What this means for enterprise technology buyers
For CTOs, technology procurement leaders, and supply chain technology managers evaluating IT services providers, the episode illustrates the verification process that followed an external threat alert. According to Business-Today, TCS received the threat-intelligence alerts, conducted an investigation, and reported to stock exchanges that the referenced data was more than four years old and limited to basic employee information, with no credible evidence of a breach found. S2W's claim remains unverified, and the alleged database's size exceeding the current workforce stands as a factual inconsistency reported by Business-Today.