TCS Says Leaked Employee Data ‘Appears To Be’ Over Four Years Old
The company stops short of confirming the age or source of the data, even as it rules out a breach of its systems.
Tata Consultancy Services (TCS) has said the employee data referenced in a recent threat-intelligence alert “appears to be” more than four years old, stopping short of confirming its exact age or origin.
The company made the statement in a filing with the Bombay Stock Exchange (BSE) on Monday, after receiving threat intelligence alerts about the possible exposure of employee information.
TCS said it has not found any credible evidence of a breach of its systems or customer environments. It added that the information referenced in the alerts is limited to basic employee details, and that there is no indication customer data, customer systems or its own operational systems have been impacted.
The alerts followed a post on X by threat-intelligence handle @S2W_DailyThreat, which flagged a listing on hacking forum BreachForums. The listing was posted by an entity identified as “TheHatman,” who claimed to have pulled the data directly from TCS’s Azure tenant using compromised credentials.
The listing alleges more than 800,000 TCS employee records are up for sale. These reportedly include full names, employee IDs, email addresses, job titles, phone numbers and addresses.
A sample of about 6,000 records was attached to the post, along with contact details on Session, Tox and Jabber for buyers. The seller is also advertising additional corporate data dumps on request.
TCS has not confirmed the authenticity of the sample or the source of the records.
Password Spray, MFA Fatigue Behind The Claim
The company said the attacker claims to have used password spraying and multi-factor authentication (MFA) fatigue as the attack vector. TCS said it has had safeguards against these techniques in place for more than two years, and that its current assessment shows these controls remain effective.
TCS’s language through the filing is qualified at several points. The company says it has “not found” credible evidence of a breach, rather than stating no breach occurred.
It says there is “no indication” of impact to customer data or systems, rather than confirming no impact took place. And it describes its controls as remaining effective “based on the current review,” a phrasing that ties the assessment to a point in time rather than closing the matter.
This pattern is consistent with how companies typically disclose under Regulation 30 of the Securities and Exchange Board of India Listing Obligations and Disclosure Requirements, which requires prompt disclosure of material events, often before a full forensic investigation is complete.
The wording leaves room for TCS’ assessment to be updated if further details emerge.
TCS said it continues to closely monitor its environment and will evaluate any new information that emerges. The company added that it will take appropriate action if required, and remains committed to protecting the information entrusted to it.
TCS did not disclose when it first received the threat-intelligence alerts, how it arrived at the four-year estimate for the data’s age, or whether it has identified the specific incident from which the older data may have originated.
The disclosure adds to a string of cybersecurity incidents involving TCS in the past year. In 2025, U.K. retailer Marks & Spencer suffered a data breach that led to the theft of customer data. The incident was initially linked to a compromise of TCS's IT systems, as TCS provides IT services to the retailer. Marks & Spencer had severed its long-running technology helpdesk partnership with TCS six months after the cyberattack.
TCS later said none of its own systems or users were compromised in that incident.
TCS is India’s largest IT services exporter by revenue and employs over 600,000 people globally. The company services several Fortune 500 clients across banking, retail and manufacturing, making any claim involving its infrastructure a matter of scrutiny for enterprise customers.
The company has not said whether it plans to notify affected employees or law enforcement agencies about the alleged exposure. It also has not clarified whether the four-year-old data originated from an earlier, previously undisclosed incident, or how the alleged records came to be listed on BreachForums.
CRN India has reached out to TCS for further comment and will update this story with any response.
This article originally appeared on CRN’s sister site CRN India.