Data Beach 2026: TCS, HCLTech, Hexaware and Others Deny Dark Web Leaks; Experts Still Not Satisfied With Answer
TCS, HCLTech, and Hexaware have denied dark web data leaks after a hacker claimed to have stolen millions of Azure employee records from major global corporations. While companies insist the data is old and systems remain secure, cybersecurity experts warn the directory dumps pose serious phishing risks.
Major IT firms including Tata Consultancy Services, HCLTech, and Hexaware Technologies have strongly denied any exposure of employee data on the dark web following claims made by a threat actor. The actor, operating under the alias 'TheHatman', leaked millions of Microsoft Azure directory records affecting multiple Fortune 500 companies. While affected corporations maintain that the leaked data is outdated and stems from uncompromised systems, cybersecurity researchers remain sceptical.
Dark Web Leak Claims and Corporate Denials
The threat actor flooded dark web forums with millions of employee records allegedly downloaded directly from Azure tenants using compromised credentials. As per a report by Moneycontrol, Indian IT majors TCS, HCLTech, and Hexaware formally notified stock exchanges confirming that internal investigations found no evidence of a system breach or customer environment compromise. GTA 6 Leaks Linked to India? Here's Truth Behind Claims on How Rockstar Games India Associated With Breaches.
Furthermore, as per a report by BleepingComputer, the exposed databases include foundational directory attributes such as names, employee IDs, email addresses, and phone numbers. Additional details concerning the compromised organizations, record volumes, and specific data types are structured below:
| Company | Size | Type | Data type |
| McDonalds | 1.7+ million records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| Gap Inc. | 80,000+ records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| Vodafone | 425,000+ records | Azure Internal Employee Dump | Full Name, Email, Title, Phone, Address |
| TCS (Tata Consultancy) | 800,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| HCL Technologies | 250,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| InterContinental Hotels | 185,000+ records | Azure dump | Full Name, Email, Title, Phone, Address |
| Wyndham Hotels | 9,000+ records | Azure/Entra dump | Full Name, Email, Title, Phone, Address |
| Hexaware | 20,000+ records | Azure/Entra dump | Full Name, Email, Employee ID, Phone, Address |
| Kyndryl.com | 170,000+ records | Azure/Entra dump | Employee accounts, service accounts, and other tenant account records. |
Cybersecurity Experts Warn of Secondary Risks
Despite official corporate assurances stating that the data is several years old and presents minimal operational risk, independent security professionals warn that directory exposures carry significant utility for malicious actors. Data Breach 2026: 149 Million Login Credentials for Gmail, Facebook and Binance Exposed Online; Cybersecurity Researcher Unsecured Database.
As per a report by TechRadar, stolen structural attributes such as reporting lines, service accounts, and global administrator names can facilitate targeted spearphishing, helpdesk impersonation, and fraudulent wire transactions. Experts emphasize that even recycled directory data remains a high-risk vector for subsequent social engineering attacks against global enterprises.
(The above story first appeared on LatestLY on Aug 21, 2026 11:57 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).