
Several major Indian IT companies including TCS, HCLTech, and Hexaware have downplayed data breaches disclosed this month, but cybersecurity experts say the commercial and reputational damage may outweigh the technical severity. Israeli…
Several major Indian IT companies including TCS, HCLTech, and Hexaware have downplayed data breaches disclosed this month, but cybersecurity experts say the commercial and reputational damage may outweigh the technical severity. Israeli cybercrime intelligence firm Hudson Rock reported that a hacker accessed the companies' Azure tenants, compromising over 800,000 records from TCS, 250,000 from HCLTech, and 20,000 from Hexaware, including employee names, IDs, emails, phones, and addresses.

The companies argue the leaked data is old and limited, a distinction experts say could help them avoid strict notification timelines and penalties under the Digital Personal Data Protection Act. However, analysts warn that even old organisation charts remain useful for social engineering attacks, and that trust is the core product Indian IT sells globally. Cognizant has acknowledged a breach from April 21 and offered affected individuals identity theft protection. Experts say AI-driven attacks require 24×7 threat monitoring instead of periodic checks.
The attacks targeted a decade of accumulated employee directory data across multiple IT firms, not just a single breach event. Under the Digital Personal Data Protection Act 2023, companies must notify the Data Protection Board of any breach within a specific timeline or face penalties of up to Rs 250 crore. The hacker's claim of accessing Azure tenants suggests a supply-chain vulnerability rather than a system flaw, since the data was stored on Microsoft's cloud infrastructure. TCS, which employs over 600,000 people, and HCLTech, with over 200,000 staff, face litigation risk from clients whose contracts include confidentiality clauses. The companies' argument that the data is old may shield them from DPDP liability only if they can prove the breach predates the Act's notification rules taking effect. The next trigger point is any client lawsuit or regulatory inquiry, as the Securities and Exchange Board of India has already required exchange filings on the matter.
Source: rediff.com
This brief was synthesised by AI from the source linked above.