News
11 - 08 - 2026
Two Indian IT majors report employee data exposure claims in quick succession
HCLTech, TCS report alleged employee data exposures, though both companies stated that any potential compromise remains limited and core systems were unaffected
Two Indian Information Technology (IT) firms, HCL Technologies (HCLTech) and Tata Consultancy Services (TCS), have reported claims of employee data exposure in short succession, but stated that the potential security incidents were limited.
HCLTech reported a potential employee data leak following claims made by a hacker group, coming shortly after rival TCS disclosed a similar alert to stock exchanges on Monday.
At a Glance
- HCLTech: No evidence of a breach to internal systems or client engagements
- TCS: No credible evidence of any compromise
- Scope of Data: Allegedly exposed records for both IT companies
- Mode: Both firms said hackers claimed to have used password spraying and multi-factor authentication fatigue
“The company’s initial investigation has revealed that the aforesaid data may be limited and dated to a few years back,” HCLTech said in a BSE statement.
“There is no evidence of breach to the Company’s systems or engagement with any of the company’s clients,” it said. The firm added that it continues to investigate the matter and will disclose any material findings from the probe.
The disclosure followed reports circulating on dark web forums and social media. A threat actor claimed to offer an HCLTech dataset containing information on over 2,50,000 employees, including full names, email addresses, job titles, departments, phone numbers, physical addresses, and employee and service account records. The attacker asserted the dataset was extracted from a Microsoft Azure Tenant using compromised credentials. The claims were noted by Intel and Breaches, an X account tracking dark web activity.
HCLTech stated that “cybersecurity remains a top priority and that it is committed to protecting information entrusted to it”.

Ditto for TCS
The announcement came hours after TCS informed stock exchanges that it had received threat-intelligence alerts regarding the potential exposure of certain employee details. TCS, India’s largest IT services firm, confirmed that its investigation found no credible evidence of a breach of its internal networks or customer environments.
Data security firm S2W reported on X that a threat actor named TheHatman had listed over 800,000 alleged TCS employee records for sale on an underground forum. Further reports indicated details including full names, employee IDs, job titles, phone numbers, and addresses were placed on BreachForums. The attacker claimed to have obtained access via TCS’s Azure tenant using compromised credentials.
“The information referenced appears to be more than four-years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted,” TCS said in the BSE filing.
TCS also said that the attacker claimed to have used password spraying and multi-factor authentication (MFA) fatigue as attack vectors. The company stated it has maintained strong safeguards against such methods for about two years.
“Based on the current review, these controls remain effective, and the company continues to monitor the environment closely,” it added.
What’s password spraying, MFA fatigue
Password spraying and MFA fatigue (also called MFA bombing or push spam) are identity-based attack vectors. In password spraying, hackers test a small list of commonly used passwords against user accounts to gain access. Once a valid password is discovered, MFA fatigue involves repeatedly sending push notifications to users’ mobile device until they accidentally or out of frustration hit ‘approve’.
Earlier, India’s major public and private sector banks such as Canara Bank, and the Indian Computer Emergency Response Team (CERT-In) actively issued cybersecurity advisories cautioning staff and retail customers against MFA fatigue. These advisories followed targeted attempts against enterprise Single Sign-On (SSO) portals and corporate Virtual Private Networks (VPNs) using automated push notification bombing.
While password spraying and MFA fatigue claims have recently surfaced in Indian IT disclosures, these tactics first gained widespread attention through global breaches that prompted Indian enterprise IT teams to upgrade their defences.
In 2022 an attacker obtained a Uber employee’s credentials via password spraying/dark web markets and continuously issued MFA push requests late at night until the employee accepted it. The breach compromised internal Slack, AWS, and GCP infrastructure.
During 2022–2023, threat groups (such as Lapsus$ and Midnight Blizzard) heavily utilised password spraying against corporate accounts lacking strict conditional access policies, followed by MFA fatigue tactics.