The Indian IT company Tata Consultancy Services (TCS), the largest in India, reported receiving alerts from threat intelligence services regarding a possible breach of information about some employees.
However, investigations conducted confirmed the absence of credible evidence of a hack into TCS systems or client environments. The company stated in documentation submitted to BSE that the information referenced is allegedly older than four years and contains only basic employee details, with no signs that client data, client systems, or TCS operating systems were affected.
TCS clarified that the attacker claimed to have used 'password spraying' and MFA fatigue attack methods. The company emphasized that it has been employing robust protective mechanisms against such techniques for over two years.
This clarification followed reports circulating on the social media platform X that full names, identification numbers, job titles, phone numbers, and addresses of employees were available on the known hacker forum BreachForums. The hacker claimed the data was obtained directly from TCS's Azure tenant using compromised credentials.
The company added that 'based on the current review, these controls remain effective, and the company continues to monitor the situation closely.'
TCS has previously been involved in disputes related to cyberattacks. Last year, the British retailer Marks & Spencer faced a customer data leak. Although it was initially suspected that this occurred due to the compromise of TCS IT systems, the company itself later stated that neither its systems nor its users were compromised.

