HCLTech and TCS: HCLTech says stolen data may be years-old after hacker’s data breach claims

HCLTech and TCS: HCLTech says stolen data may be years-old after hacker’s data breach claims

HCLTech Employee Data Allegedly Leaked in Dark Web Breach

A threat actor claimed on a dark web forum to be selling a dataset allegedly belonging to HCLTech, containing details of over 250,000 employees. The exposed information reportedly includes full names, email addresses, job titles, departments, phone numbers, physical addresses, and employee and service account records.

The hacker asserted that the data was obtained from a Microsoft Azure Tenant using compromised credentials, raising concerns about the growing sophistication of AI-driven cyberattacks. The incident follows a broader trend of enterprises bolstering their defenses in cloud security, AI security, and threat intelligence to counter evolving threats.

HCLTech denied a breach of its internal systems, stating that its investigation found the allegedly stolen data to be limited and potentially years old, with no evidence of compromise to client engagement systems. The company confirmed that its operational systems remain unaffected and that existing safeguards implemented over two years ago remain effective.

Meanwhile, TCS acknowledged receiving alerts about potential exposure of certain employee data but clarified that there was no indication of customer data or systems being impacted. The company noted that the referenced information appeared to be over four years old and limited to basic employee details.

The claims were first reported by Intel and Breaches, a dark web monitoring account on X (formerly Twitter). However, the authenticity of the data dump and the threat actor’s assertions have not been independently verified.

The incident underscores the persistent risks of credential-based attacks on cloud environments, particularly as cybercriminals leverage AI to automate and scale their operations. Both HCLTech and TCS continue to investigate the matter, with HCLTech stating that any material findings will be reported accordingly.

Source: https://indianexpress.com/article/technology/tech-news-technology/hcltech-clarification-hackers-data-breach-10827766/

HCLTech TPRM report: https://www.rankiteo.com/company/hcltech

TCS TPRM report: https://www.rankiteo.com/company/tata-consultancy-services

"id": "hcltat1786448292",
"linkid": "hcltech, tata-consultancy-services",
"type": "Breach",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '250,000 employees',
                        'industry': 'IT Services',
                        'name': 'HCLTech',
                        'type': 'Company'},
                       {'customers_affected': 'Certain employees (details not '
                                              'specified)',
                        'industry': 'IT Services',
                        'name': 'TCS',
                        'type': 'Company'}],
 'attack_vector': 'Compromised Credentials',
 'customer_advisories': 'HCLTech and TCS confirmed no impact on customer data '
                        'or systems.',
 'data_breach': {'data_exfiltration': 'Allegedly sold on dark web',
                 'number_of_records_exposed': '250,000+ (HCLTech), unspecified '
                                              '(TCS)',
                 'personally_identifiable_information': 'Full names, email '
                                                        'addresses, phone '
                                                        'numbers, physical '
                                                        'addresses, job '
                                                        'titles, departments',
                 'sensitivity_of_data': 'High (PII)',
                 'type_of_data_compromised': 'Employee data (PII, job details, '
                                             'contact information)'},
 'description': 'A threat actor claimed on a dark web forum to be selling a '
                'dataset allegedly belonging to HCLTech, containing details of '
                'over 250,000 employees. The exposed information reportedly '
                'includes full names, email addresses, job titles, '
                'departments, phone numbers, physical addresses, and employee '
                'and service account records. The hacker asserted that the '
                'data was obtained from a Microsoft Azure Tenant using '
                'compromised credentials. HCLTech denied a breach of its '
                'internal systems, stating the data was limited and '
                'potentially years old. TCS also acknowledged alerts about '
                'potential exposure of certain employee data but confirmed no '
                'impact on customer data or systems.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage',
            'data_compromised': 'Employee data (full names, email addresses, '
                                'job titles, departments, phone numbers, '
                                'physical addresses, employee and service '
                                'account records)',
            'identity_theft_risk': 'High (PII exposed)'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Allegedly sold',
                           'entry_point': 'Microsoft Azure Tenant (compromised '
                                          'credentials)'},
 'investigation_status': 'Ongoing (HCLTech and TCS)',
 'lessons_learned': 'Persistent risks of credential-based attacks on cloud '
                    'environments; need for enhanced AI-driven threat '
                    'detection and cloud security measures.',
 'motivation': 'Financial Gain (Data Sale)',
 'post_incident_analysis': {'corrective_actions': 'Enhance cloud security '
                                                  'measures, implement MFA, '
                                                  'conduct regular security '
                                                  'audits, and monitor for '
                                                  'credential leaks.',
                            'root_causes': 'Compromised credentials leading to '
                                           'unauthorized access to Azure '
                                           'Tenant; potential lack of '
                                           'multi-factor authentication or '
                                           'weak credential management.'},
 'recommendations': 'Strengthen cloud security, implement multi-factor '
                    'authentication, monitor dark web for data leaks, and '
                    'enhance employee training on credential hygiene.',
 'references': [{'source': 'Intel and Breaches (X/Twitter)'}],
 'response': {'communication_strategy': 'Public statements denying breach of '
                                        'internal systems (HCLTech) and '
                                        'clarifying limited data exposure '
                                        '(TCS)'},
 'title': 'HCLTech Employee Data Allegedly Leaked in Dark Web Breach',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Microsoft Azure Tenant'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.