Tata Consultancy Services (TCS), India’s largest IT services company, on Monday said it had received threat-intelligence alerts alleging the possible exposure of certain employee information, but stressed
that there was no credible evidence of a breach of its systems or customer environments.
The Tata group company said the information referenced in the alerts appeared to be more than four years old and was limited to “basic employee information”.
TCS also clarified that there was no indication of any impact on customer data, customer systems or its own operational systems.
TCS Investigates Alleged Employee Data Exposure
In a stock exchange notification, TCS said, “The company has received threat-intelligence alerts alleging possible exposure of certain employee information.”
The company said it had investigated the matter and, according to IANS, “has not found any credible evidence of a breach of TCS systems or customer environments.”
TCS further said the information referred to in the alerts appeared to be more than four years old and was limited to basic employee information.
“There is no indication that customer data, customer systems, or TCS operational systems have been impacted,” the company said.
Reuters reported that TCS did not provide further details on who had issued the alerts or when they were issued.
Password Spray, MFA Fatigue Cited As Alleged Attack Vectors
TCS also addressed claims about how the alleged exposure may have occurred.
According to the company, the attacker claimed to have used password spraying and Multi-Factor Authentication (MFA) fatigue as the attack vectors.
“The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector,” TCS said in its exchange filing.
The company added that it has had strong safeguards against such techniques in place for more than two years.
“Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” TCS said.
The company said it would continue assessing any new information that becomes available and would take appropriate action if required.
TCS Says Customer Systems Remain Unaffected
TCS reiterated that its investigation had not found credible evidence of a breach involving its systems or customer environments.
It also maintained that there was no indication that customer information or its operational systems had been affected.
“The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us,” TCS said, according to the IANS report.
The development nevertheless weighed slightly on TCS shares on Monday.
According to PTI, TCS shares closed 0.80 per cent lower at Rs 2,434 on the BSE, while the benchmark index gained 0.06 per cent.
The company said it would continue to monitor its environment closely and assess any fresh information linked to the threat-intelligence alerts.














