HCLTech Denies Data Breach Claims by Hacker Group, ETHRWorld

WorkAI.TV Editorial Desk
3 Min Read

Share with your CISO

HCLTech is pushing back hard against a hacker group’s claim that employee data was exposed, filing with Indian stock exchanges to say its initial investigation found no evidence of a systems breach or any impact on client engagements. The alleged data appears limited and dated several years back. The denial follows an identical pattern at TCS, where threat-intelligence alerts surfaced claims of employee data exposure via password spraying and MFA fatigue, and TCS similarly found no credible breach evidence.

What this means for your business

Two of India’s largest IT services firms issuing near-identical stock-exchange denials within days of each other is not a coincidence, and if your organization runs on either vendor’s managed services or staff augmentation, the question isn’t whether their internal HR data matters to you directly. It’s whether the same threat actors are probing the seams between your environment and theirs. Vendor breach claims, even unverified ones, are reconnaissance signals worth tracking in your own threat-intelligence feed.

The attack vectors TCS named, password spraying and MFA fatigue, deserve specific attention here. Password spraying means trying a small set of common passwords across a very large number of accounts, avoiding the lockout triggers that catch brute-force attempts. MFA fatigue means flooding a user with push-notification approval requests until they approve one just to stop the noise. Neither technique requires sophisticated tooling. Both work reliably against organizations that treat MFA as a compliance checkbox rather than an actively monitored control, and both leave forensic traces that are easy to miss if you’re not watching authentication logs in near-real time.

The detail that alleged stolen data is “limited and dated” cuts two ways. It’s genuinely reassuring if true, because stale employee records carry lower operational risk. But it also suggests the actors may be building a profile over multiple collection events across multiple targets rather than executing a single smash-and-grab. If your vendor roster overlaps with HCLTech’s or TCS’s client base, the calculus to revisit isn’t your contract terms. It’s whether your third-party access reviews are frequent enough to catch a credential that’s been quietly valid for four years.

Based on reporting from HCLTech Denies Data Breach Claims by Hacker Group, ETHRWorld, originally published 2026-08-11 08:21:00.

TAGGED:
Share This Article