Tata Consultancy Services (TCS), India’s largest IT services company, has received alerts alleging the possible exposure of certain employee-related data, but the company said there is no indication that customer data, customer systems or TCS’ operational systems have been affected.

The disclosure came on August 10 after threat-intelligence alerts raised concerns about a possible data exposure. TCS said the information referenced in the alerts appears to be more than four years old and is limited to basic employee information. The company has not disclosed how many employees may be affected or provided details about the source of the alerts.

What TCS has confirmed

TCS has described the situation as an alleged exposure of certain employee-related data, rather than confirming a successful breach of its current corporate systems.

The company said there is currently no indication that the incident affected:

  • Customer data
  • Customer systems
  • TCS operational systems

The information referenced in the alerts appears to be more than four years old and limited to basic employee information.

TCS ALERTS
     ↓
Possible employee-data exposure
     ↓
Information appears 4+ years old
     ↓
Basic employee information
     ↓
No indication of customer-data impact
     ↓
No indication of customer-system impact
     ↓
No indication of TCS operational-system impact

What type of data may have been exposed?

TCS has not provided a detailed list of the information allegedly exposed.

It has only described it as basic employee information and said the data referenced in the alerts appears to be more than four years old.

This distinction is important because employee-related information can range from relatively basic records to highly sensitive personal information.

Until TCS provides additional details, it would be premature to assume that passwords, financial information, customer information or other sensitive records were exposed.

What is known vs unknown

QuestionCurrent position
Employee data allegedly exposed?Yes, according to alerts
TCS confirmed a current systems breach?No
Customer data affected?No indication
Customer systems affected?No indication
TCS operational systems affected?No indication
Age of referenced informationMore than 4 years old
Nature of informationBasic employee information
Number of affected employeesNot disclosed
Source of alertsNot disclosed

Alleged attack method involves password spraying and MFA fatigue

TCS’ exchange filing also refers to claims that the attacker used password spraying and multi-factor authentication (MFA) fatigue as possible attack vectors.

These are established techniques used in credential-based attacks.

What is password spraying?

Password spraying involves attempting a commonly used password against many accounts rather than repeatedly attacking a single account.

Many employee accounts
        ↓
One / few commonly used passwords
        ↓
Repeated authentication attempts
        ↓
Potential account compromise

This differs from traditional brute-force attacks, where an attacker may try many passwords against one account.

What is MFA fatigue?

MFA fatigue, sometimes called MFA bombing, attempts to overwhelm a user with repeated authentication requests.

The basic idea is:

Login attempt
     ↓
MFA notification
     ↓
Another notification
     ↓
Another notification
     ↓
User becomes frustrated
     ↓
User accidentally approves
     ↓
Account potentially compromised

TCS said it has had safeguards against techniques of this nature in place for more than two years and that ongoing reviews indicate those controls remain effective.

TCS says its current safeguards remain effective

The company said it has had appropriate safeguards in place for more than two years to counter attacks involving techniques such as those referenced in the alerts.

TCS also said its ongoing reviews indicate that these controls remain effective.

This is a significant part of the company’s response because it indicates that the information referenced in the alerts does not, at this stage, appear to demonstrate a compromise of TCS’ current operational environment.

Why the age of the data matters

The fact that the referenced information appears to be more than four years old is important.

Aged employee information can still have privacy implications, but it is different from an attacker gaining access to a company’s current employee database or live customer systems.

Old employee information
        ≠
Current customer database

Old employee information
        ≠
Live operational systems

However, old data can still create risks if it contains information that remains useful for identity theft, phishing or social engineering.

Why employee data can still be valuable

Even basic employee information can potentially help attackers construct more convincing phishing campaigns.

For example:

Employee name
      +
Company information
      +
Job role
      +
Old contact information
      ↓
More convincing phishing attempt
      ↓
Potential credential theft

This is why companies generally need to protect employee data even when customer information is not involved.

Customer data remains the key concern for TCS clients

For TCS’ thousands of enterprise customers, the most important question is whether client information or client systems were affected.

TCS has specifically stated that there is no indication of an impact on customer data or customer systems.

This is particularly important because TCS provides IT services to companies across sectors including:

  • Banking
  • Financial services
  • Insurance
  • Retail
  • Manufacturing
  • Healthcare
  • Telecommunications
  • Government
  • Travel
  • Energy

A compromise of customer environments would potentially have much broader consequences than an exposure involving old employee information.

TCS’ cybersecurity framework

TCS has extensive cybersecurity and privacy controls documented in its annual reporting.

Its latest annual report says the company’s cybersecurity framework is designed around recognised standards and that its privacy framework covers employees, job applicants, customers, partners, vendors and other stakeholders whose personal data it processes.

The company also states that customer data is not used for secondary purposes and that data processing undertaken on behalf of customers is governed by contractual obligations.

TCS data-protection framework

Cybersecurity framework
        +
Privacy policies
        +
Access controls
        +
Employee training
        +
Monitoring
        +
Incident response
        ↓
Protection of employee + customer data

TCS reported that 98% of employees completed mandatory data-privacy training in FY26.

TCS has previously reported a separate cybersecurity incident

TCS’ annual reporting also records a ransomware incident involving C-Edge Technologies, a subsidiary, during the previous reporting period.

According to TCS’ filing, the incident was reported to CERT-In, the affected systems were quarantined and remedial measures were taken. The company reported no impact involving customers’ personally identifiable information from that incident.

This earlier disclosure is separate from the latest employee-data alerts.

It is important not to combine the two incidents.

The latest situation is still developing

TCS has not publicly disclosed several details surrounding the latest alerts.

Among the unanswered questions are:

  • How many employees are potentially affected?
  • Exactly what employee information was referenced?
  • Where did the information originate?
  • When was it allegedly obtained?
  • Was the information actually extracted from TCS systems?
  • Was it obtained from another source?
  • Was any current account compromised?
  • What investigation has been completed?

The company has said its reviews are continuing.

What this means for TCS customers

For customers, the immediate message is relatively reassuring.

TCS says there is currently no indication of customer-data or customer-system impact.

Latest alerts
     ↓
Employee-related information
     ↓
Appears 4+ years old
     ↓
No indication of customer-data exposure
     ↓
No indication of customer-system compromise

Customers should nevertheless continue following TCS’ security communications because investigations can evolve as additional information becomes available.

What this means for TCS employees

Current and former employees may still want to remain alert to suspicious communications.

If old employee information has genuinely been exposed, attackers could potentially use it for targeted phishing or social-engineering attempts.

Employees should be particularly cautious about:

  • Unexpected password-reset requests
  • Suspicious MFA prompts
  • Emails requesting credentials
  • Messages asking for confidential information
  • Unusual login alerts
  • Links requesting authentication

The reported reference to MFA fatigue makes unexpected authentication requests particularly relevant.

Why MFA fatigue is a growing cybersecurity problem

Multi-factor authentication significantly improves account security, but it is not completely immune to social engineering.

An attacker who has obtained a username and password may attempt to trick the legitimate user into approving an MFA request.

This means modern cybersecurity increasingly requires both:

technical controls + user awareness.

Strong password
      +
MFA
      +
Device security
      +
User awareness
      +
Monitoring
      ↓
Stronger account protection

India’s IT sector faces increasing cyber risks

The incident comes at a time when India’s large IT-services companies are becoming increasingly important targets for cybercriminals.

These companies manage huge volumes of data and operate technology environments connected to some of the world’s largest corporations.

That makes them attractive targets for:

  • Credential theft
  • Ransomware
  • Supply-chain attacks
  • Social engineering
  • Data theft
  • Extortion
  • Account takeover

The scale of India’s IT-services industry means a serious cyber incident at a major provider could potentially have consequences beyond the company itself.

Why TCS is particularly sensitive

TCS is India’s largest IT-services company and has a huge global workforce.

Its clients rely on the company for technology infrastructure, software development, cloud services, cybersecurity, business processes and digital transformation.

That makes trust a critical part of its business model.

TCS
 ↓
Large employee base
 ↓
Global customers
 ↓
Sensitive enterprise environments
 ↓
High cybersecurity responsibility

Even an incident that does not affect customer systems can therefore attract significant attention.

The bigger issue is data hygiene

The reference to information that is more than four years old also raises a broader question around how long companies retain employee information and how securely legacy data is managed.

Organisations need to balance:

legal retention requirements

with

data-minimisation principles.

The longer information remains stored, the longer it potentially remains exposed to future security threats.

Data lifecycle

Data created
    ↓
Active use
    ↓
Archived
    ↓
Retention period
    ↓
Secure deletion

Strong data-governance practices should cover every stage of this lifecycle.

What businesses can learn from the incident

The reported situation highlights several cybersecurity priorities for large organisations.

1. Protect old data

Legacy databases should receive the same security attention as current systems.

2. Strengthen MFA

Companies should implement phishing-resistant authentication where possible.

3. Monitor unusual login activity

Password spraying can often be detected through abnormal authentication patterns.

4. Train employees

Users need to recognise suspicious MFA requests and phishing messages.

5. Minimise data retention

Information that no longer needs to be retained should be securely deleted in accordance with applicable requirements.

6. Separate customer environments

Strong segmentation can help prevent an employee-account compromise from spreading into customer or operational systems.

TCS situation at a glance

AreaCurrent status
Alleged employee-data exposureUnder review
Data ageMore than 4 years old
Data described asBasic employee information
Customer dataNo indication of impact
Customer systemsNo indication of impact
TCS operational systemsNo indication of impact
Alleged attack techniquesPassword spraying + MFA fatigue
Current safeguardsTCS says they remain effective
InvestigationOngoing

What to watch next

The most important developments will be whether TCS provides additional information about the alleged exposure.

Key questions include:

  • Whether the company confirms an actual data breach
  • The number of affected employees
  • The exact categories of data involved
  • Whether any current accounts were compromised
  • Whether law-enforcement or cybersecurity authorities are involved
  • Whether any customer systems are subsequently found to have been affected
  • Whether TCS introduces additional security measures

Until those questions are answered, the incident should be described as an alleged exposure based on threat-intelligence alerts, rather than a confirmed compromise of TCS’ customer or operational systems.

Conclusion

TCS has received alerts alleging that some employee-related data may have been exposed, but India’s largest IT-services company has said there is no indication that customer data, customer systems or its operational systems have been affected. The information referenced in the alerts appears to be more than four years old and limited to basic employee information.

The alerts reportedly refer to password spraying and MFA fatigue as possible attack methods. TCS said it has had safeguards against such techniques in place for more than two years and that its ongoing reviews indicate those controls remain effective.

For TCS customers, the absence of any indication of customer-data or customer-system impact is the most important takeaway. For employees, however, any exposure of old personal information could still create risks around phishing and social engineering.

The incident also highlights a broader cybersecurity challenge for large enterprises: protecting data does not end when the information becomes old. Legacy employee databases can remain valuable to attackers and may need to be protected, monitored and eventually securely deleted.

For now, the situation remains under review. The critical distinction is between an alert alleging exposure of old employee information and a confirmed breach of current TCS systems. Based on the company’s latest disclosure, there is currently no indication that customer data or operational systems were compromised.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.