Business

Tata Consultancy Services Security Alerts: TCS Says No Evidence of Breach, Customer Data Safe

Tata Consultancy Services said it received threat-intelligence alerts alleging possible exposure of employee-related data but found no credible evidence of a breach of its systems or customer environments. TCS said the information appears to be more than four years old and limited to basic employee data. The company said customer data and systems were not impacted.

Tata Consultancy Services Security Alerts: TCS Says No Evidence of Breach, Customer Data Safe
TCS | Tata Consultancy Services Logo (Photo Credits: Official Website)
1
2
3
4
5

Tata Consultancy Services (TCS) on Monday, August 10, said it had received threat-intelligence alerts alleging the possible exposure of certain employee-related data, but said its investigation found no credible evidence that its systems or customer environments had been breached. The company also said there was no indication that customer data or systems had been compromised.

In a regulatory filing, TCS said the information referenced in the alerts appeared to be more than four years old and was limited to basic employee information. The company said it had investigated the matter and would continue monitoring its environment and assessing any new information that becomes available. Tata Consultancy Services Opening Bell Updates: Mixed Cues for IT Major.

TCS Says Customer Data Not Affected

TCS said its investigation did not identify evidence of a compromise involving its systems or customer environments. "The information referenced appears to be more than four years old and limited to basic employee information," TCS said, adding that "There is no indication that customer data, customer systems, or TCS operational systems have been impacted."

The company said it was continuing to assess the information associated with the threat alerts. Infosys Opening Bell Updates: Global Cues, AI Deals Drive INFY Outlook.

Password Spray, MFA Fatigue Allegedly Cited

According to TCS, the attacker claimed to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector.

Password spraying involves attempting commonly used passwords against multiple accounts, while MFA fatigue attacks attempt to overwhelm users with repeated authentication prompts in the hope that a legitimate user eventually approves one.

"The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely," TCS said. Such techniques have been documented as methods used by threat actors to target accounts protected by authentication controls.

Company Continues Security Review

TCS said it would continue to assess any new information that becomes available and take appropriate action, if required. "The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us," TCS said.

The company has previously described its cybersecurity programme as including threat-intelligence monitoring, AI/ML-based security tools, vulnerability assessments, penetration testing and 24x7 monitoring through its Cyber Security Operations Center.

No Evidence of Customer-System Compromise

The latest disclosure comes amid increased scrutiny of cybersecurity risks facing large technology and IT-services companies.

For TCS, however, the current investigation has not found evidence that customer data, customer systems or TCS operational systems were affected. The company said the employee-related information referenced in the alerts was more than four years old. TCS said it would continue monitoring the environment and take further action if its assessment identifies any new credible information.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (Reuters), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Aug 10, 2026 08:07 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).