3 weeks ago
HCLTech, TCS say no evidence of breach after hacker claims
Some hackers said they might have gotten hold of private information about people who work at two big Indian technology companies.
The companies are called HCLTech and TCS.
The companies checked their computer systems very carefully.
Both companies say they found no proof that hackers broke into their systems.
HCLTech said any information the hackers talked about was probably old and very limited.
TCS said the information seemed to be more than four years old and was just basic employee details.
They also said customer information was not harmed.
The hackers reportedly used tricks like guessing passwords and overwhelming people with login requests.
Both companies take computer safety very seriously and are still looking into what happened.
HCLTech said its initial investigation found no evidence of a breach of its systems or client engagements after a hacker group claimed potential exposure of limited employee-related data.
HCLTech stated the allegedly exposed data may be limited and dated to a few years back, and that its investigation is continuing with material findings to be reported to stock exchanges.
Peer Tata Consultancy Services (TCS) issued a similar clarification, saying it found no credible evidence of a breach of its systems or customer environments.
TCS said the information referenced in threat-intelligence alerts appeared to be more than four years old and was limited to basic employee information.
The alleged attacker reportedly claimed to have used password spraying and multi-factor authentication (MFA) fatigue as attack vectors; HCLTech shares were trading higher at Rs 1,371 apiece on the BSE.
- Who
- HCLTech and Tata Consultancy Services (TCS), responding to claims by an unidentified hacker group.
- What
- Both IT firms said initial investigations found no evidence of a systems breach following hacker group allegations about potential exposure of employee-related data.
- Where
- India; statements were made in stock exchange filings, with HCLTech shares trading on the BSE.
- When
- HCLTech issued a filing dated 10 August; TCS disclosed its clarification on a Monday, and the alleged data may date back several years.
- Why
- The companies responded to media reports and threat-intelligence alerts citing hacker group allegations of possible exposure of limited employee data elements.
Hacker group's claims
Companies' clarifications
Employee data exposure
Hacker group's claims
A hacker group claimed potential exposure of limited employee-related data from HCLTech, and threat-intelligence alerts alleged possible exposure of certain TCS employee information, reportedly using password spraying and MFA fatigue.
Companies' clarifications
HCLTech and TCS said initial investigations found no evidence of a breach of their systems or client engagements, describing any referenced data as old, limited, and basic employee information.
Key facts
- Companies involved
- HCLTech and Tata Consultancy Services (TCS)
- HCLTech finding
- No evidence of systems breach or impact on client engagements
- TCS finding
- No credible evidence of breach of systems or customer environments
- Alleged data age
- Limited and dated; TCS said information appeared more than four years old
- Alleged attack vectors
- Password spraying and multi-factor authentication (MFA) fatigue
- TCS safeguards
- Safeguards against the claimed techniques in place for more than two years
- HCLTech share price
- Trading higher at Rs 1,371 apiece on the BSE
- Investigation status
- Ongoing at both companies, with material findings to be disclosed if any
Quotes
HCLTech spokesperson
Official representing HCLTech
“The company considers cyber security as its top priority and remains committed to protecting the information entrusted to it.”
thehansindia.com
“The company’s initial investigation has revealed that the aforesaid data may be limited and dated to a few years back.”
thehansindia.com










