Cognizant has notified individuals whose personal information may have been exposed in a data breach that occurred around April 21, 2026. The Nasdaq-listed IT services company said it has “no reason to believe” the information was misused but decided to notify potentially affected individuals as a precaution. The company has not disclosed how many people were affected or exactly what categories of personal information may have been exposed.

Cognizant is offering affected individuals 24 months of identity-theft protection through IDX, including credit and CyberScan monitoring, identity-recovery assistance and an insurance reimbursement policy of up to $1 million for eligible losses. The company has also advised recipients to monitor their financial accounts and credit reports and consider additional protections such as fraud alerts or credit freezes.

Cognizant Confirms April 21 Data Breach

The breach occurred around April 21, according to notifications sent to affected individuals by Cognizant’s U.S. entity.

The company apologized for the incident and said it was notifying customers even though it currently has no reason to believe the compromised information was misused.

Cognizant Data Breach At A Glance

ParticularDetails
CompanyCognizant Technology Solutions
Incident dateAround April 21, 2026
Notification dateAugust 2026
NatureData security breach
Potentially exposed informationPersonal information
Number of affected individualsNot disclosed
Misuse confirmedNo evidence reported
Identity protection24 months
ProviderIDX
Insurance coverageUp to $1 million
Credit monitoringIncluded
CyberScan monitoringIncluded

The lack of publicly disclosed figures means the full scale of the incident remains unclear.

Company Has Not Disclosed Number Of Affected People

One of the most significant unanswered questions is how many individuals may have been affected.

Cognizant’s notification does not specify the number of people whose information may have been exposed. It also does not publicly detail the categories or volume of personal information involved.

What Is Known And Unknown

QuestionCurrent Information
When did the breach occur?Around April 21, 2026
Was personal information potentially exposed?Yes
How many people were affected?Not disclosed
What specific data was exposed?Not disclosed by Cognizant
Has misuse been confirmed?No
Has Cognizant notified affected individuals?Yes
Is identity protection being offered?Yes

This distinction is important because reports circulating online about the incident may contain claims that have not been confirmed by Cognizant.

Cognizant Says There Is No Evidence Of Data Misuse

Cognizant told affected individuals that it has no reason to believe their information was misused.

However, the company has still chosen to notify them and provide protective services.

This approach allows potentially affected customers to take precautionary measures even when there is no confirmed evidence of identity theft or fraud linked to the incident.

Customer Protection Measures

  • 24 months of identity-theft protection
  • Credit monitoring
  • CyberScan monitoring
  • Identity-theft recovery assistance
  • Up to $1 million in insurance reimbursement for eligible losses
  • Guidance on monitoring accounts and credit reports
  • Information about fraud alerts and credit freezes

The company has also advised affected individuals to remain alert for suspicious activity.

Up To $1 Million Insurance Coverage Offered

One of the most notable aspects of Cognizant’s response is the insurance protection offered to affected individuals.

The IDX package includes an insurance reimbursement policy of up to $1 million for eligible losses arising from identity theft. It also includes managed identity-recovery services.

IDX Protection Package

ProtectionCoverage
Credit monitoringIncluded
CyberScan monitoringIncluded
Identity recoveryIncluded
Duration24 months
Insurance reimbursementUp to $1 million
ProviderIDX

The $1 million figure is a maximum coverage amount and does not mean every affected individual will receive $1 million.

Customers Advised To Monitor Credit Reports

Cognizant has advised recipients to monitor their account statements and credit reports for unusual activity.

The company also explained that affected individuals can place fraud alerts or security freezes with major credit-reporting agencies.

A credit freeze can prevent credit-reporting agencies from releasing information from a consumer’s credit report without authorization. However, Cognizant’s notification also cautioned that a freeze can delay or interfere with applications involving loans, mortgages, employment, housing and other services.

Recommended Precautions

ActionPurpose
Monitor bank/account statementsDetect suspicious transactions
Check credit reportsIdentify unauthorized activity
Fraud alertWarn potential creditors about identity concerns
Security freezeRestrict access to credit files
Identity monitoringDetect potential misuse
Report suspected identity theftBegin formal recovery process

Cognizant Has Not Explained How The Breach Occurred

Another major unanswered question is the exact mechanism behind the incident.

Cognizant’s notification does not explain whether the breach resulted from an external cyberattack, unauthorized access, compromised credentials or another security event. The company also has not publicly detailed which systems were involved.

This limits the amount of information currently available about the technical cause of the breach.

Details Still Unclear

  • Initial attack vector
  • Systems accessed
  • Number of affected individuals
  • Specific categories of exposed information
  • Volume of information potentially accessed
  • Whether an external threat actor was responsible
  • Whether any information was actually downloaded or misused

These details could become clearer if Cognizant or regulators release additional information.

Threat Actor Claim Has Not Been Independently Confirmed

Separate reporting has linked the incident to a threat actor group called CoinbaseCartel.

According to ClaimDepot, the group claimed responsibility and reportedly posted information concerning Cognizant on a dark-web site. However, Cognizant’s notification does not confirm the group’s involvement or explain how the breach occurred.

This distinction is important: a threat actor’s claim is not, by itself, confirmation that the group successfully breached a company’s systems.

Confirmed Vs Unconfirmed Information

InformationStatus
April 21 security incidentConfirmed by Cognizant notification
Potential exposure of personal informationConfirmed
Customer notificationsConfirmed
No known misuseStated by Cognizant
CoinbaseCartel involvementReported claim, not confirmed by Cognizant
Exact attack methodNot disclosed
Number affectedNot disclosed
Specific data exposedNot disclosed

Incident Comes Amid Broader IT-Sector Cybersecurity Concerns

The Cognizant disclosure comes as cybersecurity and alleged data-leak claims have received increased attention across India’s IT services industry.

Recent reports have also involved Tata Consultancy Services, HCLTech and Hexaware, although companies have denied some allegations concerning employee or organizational data leaks.

For large IT services companies handling data for global customers, cybersecurity has become an increasingly important business and reputational issue.

Why IT Services Companies Are Attractive Targets

FactorRisk
Large customer databasesHigh-value information
Global operationsMultiple attack surfaces
Enterprise accessPotential access to client environments
Third-party systemsAdditional vulnerabilities
Cloud infrastructureComplex security requirements
Remote workforceCredential and access risks

The scale and complexity of global IT operations make cybersecurity a continuous operational requirement rather than a one-time compliance exercise.

Cognizant Faced A Separate Breach At Its TriZetto Unit

The latest incident should not be confused with a separate data breach involving Cognizant subsidiary TriZetto Provider Solutions (TPS).

Earlier this year, TPS disclosed a breach that potentially affected approximately 3.4 million individuals. That incident involved a web portal used by healthcare-provider customers to access TPS systems.

The earlier breach potentially exposed sensitive information including names, addresses, dates of birth, Social Security numbers, health-insurance member numbers and other health-related information.

Cognizant-Related Data Incidents

IncidentReported Impact
April 2026 Cognizant breachNumber affected not disclosed
TPS breachAbout 3.4 million individuals
TPS data involvedPersonal and certain protected health information
Latest Cognizant responseIdentity-theft protection and $1 million coverage

These are separate incidents and should not be combined when assessing the scale of the latest Cognizant breach.

TPS Breach Was Detected Earlier

The TriZetto incident followed suspicious activity detected in October 2025.

According to the company’s disclosures, an unauthorized actor may have accessed certain records beginning in November 2024. TPS investigated the incident, involved external cybersecurity experts and notified law enforcement.

The company said the compromised records were associated with insurance eligibility verification transactions used by healthcare providers.

The earlier case demonstrates why the nature of the information involved is an important factor when assessing the consequences of a cybersecurity incident.

Why The Latest Breach Matters For Cognizant

Cognizant serves large enterprises across multiple industries, meaning trust and data security are important components of its business relationships.

Even when a breach does not result in confirmed misuse, the company may face costs associated with investigation, notification, customer support, legal compliance, monitoring services and strengthening security controls.

Potential Business Impact

AreaPotential Impact
Customer trustIncreased scrutiny
Cybersecurity spendingHigher defensive costs
ComplianceNotification and regulatory obligations
InsurancePotential claims
Legal exposurePossible investigations or claims
ReputationGreater attention from customers and investors
OperationsAdditional security and monitoring measures

The actual financial impact of the latest incident cannot yet be determined from the publicly available information.

Data Breaches Are Becoming More Expensive To Manage

A modern data breach can create costs well beyond the initial technical incident.

Companies may need to investigate the intrusion, determine which individuals are affected, notify customers, provide credit monitoring and identity protection, cooperate with regulators and potentially defend legal claims.

Cognizant’s offer of two years of identity protection demonstrates how breach-response costs can extend well beyond the date on which unauthorized access occurred.

What Affected Customers Should Watch For

Cognizant has specifically advised affected individuals to monitor their accounts and credit reports.

Recipients of the company’s notification should also be cautious about unsolicited emails, messages or calls requesting additional personal information.

A breach notification itself can sometimes be followed by phishing attempts that exploit public awareness of the incident.

Warning Signs

  • Unexpected password-reset requests
  • Unrecognized financial transactions
  • New credit accounts
  • Unfamiliar loan applications
  • Suspicious emails referencing the breach
  • Unexpected calls requesting identity information
  • Changes to account details without authorization

Customers should use contact information contained in official Cognizant or IDX communications rather than relying on unsolicited messages.

Credit Freeze Can Offer Additional Protection

Cognizant’s notification explains that affected individuals can place a security freeze on their credit files.

A freeze can make it more difficult for criminals to open new credit accounts using stolen information because lenders generally cannot access the relevant credit report without authorization.

However, consumers need to remember that a freeze can also complicate legitimate applications for credit, housing, employment and other services.

Cognizant’s Response Could Evolve

Because the company has not disclosed the number of affected individuals or detailed the information involved, additional details could emerge as the investigation and notification process progresses.

The company’s current position is that there is no reason to believe the information has been misused.

Future disclosures could clarify the technical cause, scope of exposure and whether any confirmed fraud or identity theft has been connected to the incident.

The Bigger Picture

Cognizant’s notification of an April 21 data breach highlights the growing importance of cybersecurity for large IT-services companies handling sensitive information. The company has not disclosed the number of affected individuals, the exact information potentially exposed or how the breach occurred, but it has confirmed that personal information may have been compromised. Cognizant says there is currently no reason to believe the information was misused.

The company is offering affected individuals 24 months of identity-theft protection through IDX, including credit and CyberScan monitoring, identity-recovery services and up to $1 million in eligible insurance reimbursement. The disclosure is separate from the earlier TriZetto Provider Solutions breach that potentially affected about 3.4 million individuals.

Looking Ahead

The key issue for Cognizant will be determining and communicating the full scope of the April incident. Customers and regulators will likely want more information about the systems involved, the categories of information potentially exposed and whether the investigation identifies any evidence of unauthorized use. Until those details are disclosed, the exact scale and financial consequences of the breach remain uncertain.

For affected individuals, the immediate priority is monitoring accounts and credit reports and using the identity-protection services offered by Cognizant. For Cognizant and other IT-services companies, the incident reinforces the need for strong access controls, continuous monitoring and rapid breach-response systems as cyber threats increasingly target organizations with access to large volumes of sensitive information

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.