TCS Dismisses Data Leak Allegations, Citing No Credible Breach Found
BENGALURU

Tata Consultancy Services (TCS) has issued a formal statement to stock exchanges, addressing recent threat-intelligence alerts alleging a potential exposure of employee information. The IT behemoth, however, asserted that its comprehensive internal investigation has yielded no credible evidence of a breach within its systems or its customers’ operational environments.
The company’s disclosure on Monday follows a high-profile post by the data security firm S2W on the social media platform X. S2W’s alert highlighted claims made by a threat actor, identified as “TheHatman,” who purportedly offered over 800,000 TCS employee records for sale on a clandestine cybercrime forum. The threat actor specifically claimed the data was exfiltrated from TCS’s Azure environment through the use of compromised credentials.
However, the sheer volume of the alleged data raises immediate questions. With TCS currently employing approximately 590,000 individuals, the reported figure of 800,000 records significantly exceeds the company’s entire global workforce. This discrepancy introduces a substantial element of doubt regarding the veracity and scale of the alleged breach.
According to S2W, the purported dataset encompasses a range of sensitive personal and professional details, including employee names, identification numbers, email addresses, job titles, phone numbers, and residential addresses. To substantiate the claim, TheHatman reportedly attached a sample comprising around 6,000 records and indicated a negotiable price for the complete database.
S2W’s analysis further suggested that claims of accessing an Azure tenant via compromised credentials could signify “access brokering and resale of stolen data.” It is important to note that these allegations, as presented by S2W, have not been independently verified by external sources.
In its official communication to the stock exchanges, TCS emphasized that the information referenced in the threat alerts appears to be considerably outdated, potentially more than four years old. Furthermore, the company clarified that the alleged data is limited to “basic employee information,” suggesting that critical or highly sensitive data may not be implicated.
TCS reiterated its commitment to cybersecurity vigilance, stating that it will continue to meticulously monitor its digital environment. The company also affirmed its readiness to assess any new information that may emerge and to take appropriate action should it be deemed necessary. This proactive stance underscores TCS’s dedication to safeguarding its data and that of its stakeholders.
This incident unfolds amidst a period where TCS has faced heightened scrutiny concerning cybersecurity. The company has recently been linked to security incidents affecting some of its high-profile clients, notably Jaguar Land Rover (JLR) and Marks & Spencer (M&S). These prior events underscore the increasing sophistication of cyber threats targeting large enterprises and the imperative for robust security protocols.
