Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > TCS Denies Data Breach After Hacker Claims Leak of 800,000 Employee Records

TCS Denies Data Breach After Hacker Claims Leak of 800,000 Employee Records

By: Jordan Vector Cybersecurity Expert

Last updated: August 11, 2026

Human Written
TCS Denies Data Breach After Hacker Claims Leak of 800,000 Employee Records
  • A threat actor claimed to sell hundreds of thousands of TCS records allegedly pulled from an Azure tenant using stolen credentials.

  • TCS filed a stock exchange report stating internal audits found no evidence of a breach across internal or client systems.

  • Investigations indicated that the leaked data appears over four years old and contains basic employee details rather than sensitive client files.

A representative from a hidden cybercrime forum has purportedly come forward to say that they are in possession of over eight hundred thousand employee data belonging to Tata Consultancy Services (TCS). They claimed to have acquired this confidential information through hacking into the Microsoft Azure account of TCS using a compromised user account.

Tata Consultancy Services has addressed the fears of the public via an official stock exchange disclosure on Monday. The firm stated that they’ve properly investigated the claims and found no evidence of a data breach in their systems.

Unpacking the Alleged Cloud Data Leak Details

The criminal posted the dataset on a major dark web site. The listing claimed that the breached data included complete facts about both current and former employees. Exposed fields allegedly include full names, worker identification codes, corporate email addresses, job titles, specialized department assignments, personal telephone numbers, and residential addresses.

This type of cloud-based data exposure claim follows a similar pattern seen in an incident involving EcoGPT, where a hacker alleged that a misconfigured Firebase database exposed user conversations. The claimed data breach highlighted how cloud storage misconfigurations can lead to sensitive data exposure.

The seller also claimed that the file dump contains account credentials, service account records, and administrative tenant configurations. To prove the validity of the intrusion, the hacker published a sample dataset containing approximately six thousand individual employee entries. They invited interested buyers to contact them directly through encrypted messaging channels to negotiate a final purchase price.

Some experts observed discrepancies in the details the criminal gave on the total record count. The IT consulting company has around 600,000 employees currently. Thus, the posted number of records from the threat actor exceeds the number of employees in the company.

Moreover, independent researchers noted that the hacker provided no direct technical proof confirming live access inside the cloud environment of the company. Intelligence teams warn that online sellers frequently recycle older leaked databases while claiming fresh cloud compromises to demand higher prices from buyers.

Attack Vectors and Corporate Response to Cyber Claims

In their regulatory filing, company leaders addressed the specific technical methods that the hacker claimed to use during the breach. The threat actor claimed to gain entry through password spraying techniques and multi-factor authentication fatigue tactics.

Password spraying requires trying out very common passwords until they pass the security checks. Multi-factor authentication fatigue depends on sending repeated approval prompts until a user gets tired and accidentally approves access.

Consequently, the company reviewed its internal identity controls and logging history across all regional offices. Executive management confirmed that the business implemented automated safeguards against password spraying and push notification spam over two years ago. Technical audits show that these identity protection systems remain active and fully effective.

Furthermore, internal security teams evaluated the sample data and determined that the exposed information appears more than four years old. The organization has confirmed that the dataset includes just contact information and not any sensitive data. Also, it stated that no customer information or operational network suffered any compromise.

Broader Implications for Enterprise Cloud Security and Identity Controls

This incident underscores the constant pressure that global technology service providers face from malicious actors targeting cloud accounts. IT service providers handle critical systems for Fortune 500 companies in banking, retail, and manufacturing sectors. Compromising a major IT contractor could potentially grant attackers indirect paths into downstream corporate client networks.

Notably, the dark web is rife with data brokers who are on the lookout for genuine employee credentials which they can then pass on to ransomware gangs for initial access to corporate networks. This means that companies suffer more exposure to endless attacks depending solely on basic modes of receiving SMS or contact notifications from accounts of users.

Therefore, enterprises must regularly clean up inactive user directories, retired service accounts, and former worker records. Leaving legacy employee accounts active inside central identity directories gives threat actors easy targets during brute-force campaigns. Regular credential audits reduce the overall attack surface across enterprise cloud environments.

Besides enforcing strict password policies, security teams need continuous log monitoring to spot unusual identity activity instantly. Tracking systems can identify cases in quick timeframes if an account is trying to log in from far-off places. Detecting credential misuse early enables admins to disable hacked accounts prior to the thieves stealing corporate data.

In addition, company leaders should keep the process of communicating with regulators straightforward and open each time a threat occurs. Promptly investigating dark web claims helps companies reassure corporate clients and prevent unnecessary panic across global financial markets. Proactive threat hunting ensures that legacy data exposures do not compromise active enterprise operations.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.