Two of India’s leading IT services firms, TCS and HCL, recently disclosed security incidents involving employee records, emphasizing that client environments and data were not compromised.
In a formal regulatory filing, TCS stated it had responded to “threat-intelligence alerts alleging possible exposure of certain employee information.” Following an internal investigation, the company reported “no credible evidence of a breach of TCS systems or customer environments,” clarifying that the exposed records contained outdated, basic employee details originating from over four years ago.
The disclosure noted that the threat actor reportedly employed tactics such as password spraying and multi-factor authentication (MFA) fatigue to harvest the information.
