
HCLTech told stock exchanges on Monday that its initial investigation found no evidence of a system breach or client impact, following a hacker group's claim that it accessed employee data. The company…
HCLTech told stock exchanges on Monday that its initial investigation found no evidence of a system breach or client impact, following a hacker group's claim that it accessed employee data. The company said the data in question 'may be limited and dated to a few years back'. The clarification came a day after rival TCS made a similar disclosure, saying threat-intelligence alerts flagged potential exposure of employee information that appeared over four years old.

TCS said the attacker claimed to use password spraying and MFA fatigue methods, but the company confirmed it has safeguards against these. Neither firm has identified the hacker group, explained how data was allegedly obtained, or stated whether affected employees, regulators, or law enforcement have been notified. The claims remain unverified, and both investigations are ongoing. Medianama reports that the HCLTech hacker allegedly accessed over 2,50,000 employee records from a Microsoft Azure tenant.

The stock-market filings from HCLTech and TCS follow a familiar pattern: deny a system breach, dismiss leaked data as old, and promise more investigation. Yet neither company has named the hacker group, explained how credentials were obtained, or told employees if their data was exposed. This leaves a gap that narratives of 'no impact' do not fill. The real test will come when the ongoing investigations conclude: will either firm confirm a specific attack vector, or will the trail simply go cold?
Sources (2): economictimes.indiatimes.com, medianama.com
This story was synthesised by AI from the 2 sources linked above.
Updated: this story now draws on 2 sources.