Hours after IT giant Tata Consultancy Services (TCS) said it had received threat-intelligence alerts alleging possible exposure of certain employee information,
HCLTech also said its initial investigation found no evidence of a breach of its systems or those of its clients. In a statement to the stock exchanges, HCLTech stated, "this is with reference to some media alerts regarding claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees. In this regard this is to clarify that the company’s initial investigation has revealed that the aforesaid data may be limited and dated to a few years back. There is no evidence of breach to the company’s systems or engagement with any of the company’s clients. The company, however, is undertaking further investigation, and any material findings in this regard will be reported. The company considers cyber security as its top priority and remains committed to protecting the information entrusted to it." Earlier, TCS had also mentioned how the company had investigated such a matter and did not find any credible evidence of a breach. In a statement to the stock exchanges, TCS said, "this is to inform you that the company has received threat-intelligence alerts alleging possible exposure of certain employee information. The company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted. The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the company continues to monitor the environment closely. The company will continue to assess any new information that becomes available and take appropriate action, if required. The company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us." Analysts believe such claims warrant continued monitoring, but the absence of evidence of system or client breaches at TCS and HCLTech limits the immediate risk assessment at the moment.














