TCS Finds No Evidence of Data Breach
TCS investigates threat alerts, finds no breach. Employee info exposed is over 4 years old.

Tata Consultancy Services (TCS), India's largest IT services company, has found no credible evidence of a breach of its systems or customer environments following threat-intelligence alerts.
The alerts alleged the possible exposure of certain employee information.
In a stock exchange filing, TCS said it had investigated the alerts and found that the information referred to in the claims appeared to be more than four years old and was limited to basic employee information.
The company stated that there is no indication that customer data, customer systems, or TCS operational systems have been impacted.
The attacker claimed to have used password spraying and Multi-Factor Authentication (MFA) fatigue as the alleged attack vectors. However, TCS said it has had safeguards against such techniques in place for more than two years.
Based on its current assessment, these controls remain effective, and the company continues to monitor the environment closely.
TCS will continue to assess any new information that becomes available and take appropriate action, if required.
The company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to it.
This incident highlights the importance of cybersecurity in the IT industry, particularly for large companies like TCS that handle sensitive customer data.
The fact that the exposed employee information is over four years old suggests that the company's security measures have been effective in preventing any major breaches.
However, the incident also serves as a reminder of the ongoing threats to cybersecurity and the need for companies to remain vigilant and proactive in protecting their systems and data.
In recent years, there have been several high-profile cyberattacks on Indian companies, highlighting the need for robust cybersecurity measures.
TCS's response to the threat alerts demonstrates its commitment to cybersecurity and its efforts to protect its systems and data.
The company's decision to investigate the alerts and transparently disclose its findings is a positive step towards maintaining trust with its customers and stakeholders.
Overall, the incident serves as a reminder of the importance of cybersecurity and the need for companies to prioritize it in their operations.
Frequently asked questions
What type of attack did the attacker claim to have used?
The attacker claimed to have used password spraying and Multi-Factor Authentication (MFA) fatigue as the alleged attack vectors.
How old is the exposed employee information?
The exposed employee information is more than four years old.