Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Economic Times
The Economic Times

TCS says received alerts alleging exposure of some employee data

Tata Consultancy Services on Monday reported a possible exposure of certain employee-related data, but said there ⁠was ⁠no proof of any impact on customer data or systems.

The company, India’s largest IT services provider, said it received “threat-intelligence alerts” claiming possible exposure of certain employee information. “The company investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” it said in a filing with stock exchanges.

The information referenced in the alerts appeared to be more than four years old and limited to “basic employee information”, TCS said, without providing further details on the timing and sender of the alert.

It is claimed that the employee data breach was through an attacker who reportedly used password spraying and multifactor authentication fatigue as the attack vector.

Mumbai-headquartered TCS, which provides software and IT services to large multinationals mainly in the US and Europe, assured it had safeguards in place for over two years against the manner in which this attack was carried out and that its own operational systems have not been impacted.

“Based on the current review, these controls remain effective, and the company continues to monitor the environment closely,” it added.

The company will continue to assess any new information that becomes available and take appropriate action, if required, TCS said.

Technology service outsourcers like TCS are beefing up their cyber resilience as cyberattacks and data breach incidents have seen a substantial rise with the widespread adoption of new digital technologies. There is also an increase of data breaches as artificial intelligence-based agents get used more extensively across businesses.

In April 2025, TCS reportedly suffered a major blow after a cyber incident was highlighted by customer Marks & Spencer (M&S) that led to significant data theft and weeks-long disruption of online operations of the British retail giant.

The data breach forced M&S to halt online orders, suspend parts of its click-and-collect operations and, by some reports, left store shelves understocked. The attacker group was identified as Scattered Spider, which exploited a vendor route.

M&S later ended its service contract with TCS following the attack that a media report estimated to have cost £300 million from the disruption in operations.

TCS claimed the report to be factually incorrect and maintained public denial of any involvement in the cyberattack.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.