HCLTech, a major IT services provider, completed an investigation that found no evidence of a breach of its systems or customer data, despite public claims by a hacker group alleging employee data exposure. The company issued a stock exchange disclosure on August 10–11, 2026, disputing the allegations and confirming that its independent investigation uncovered no credible compromise of current systems or client engagements. This investigation follows a similar clearance by Tata Consultancy Services (TCS), another large IT services firm, which investigated parallel threat-intelligence alerts with the same conclusion: no breach of company systems or customer environments. Both findings help clarify what actually happened after public allegations that could have affected trust in these firms.
Table of Contents
- What Did the Hacker Group Claim?
- What Did the Investigations Find?
- What Safeguards Are in Place?
- What Does This Mean for Customers and Employees?
- What Are the Limits of These Clearances?
- Frequently Asked Questions
What Did the Hacker Group Claim?
A threat actor publicly alleged that they had accessed employee data at both TCS and HCLTech using two specific attack methods: password spraying (testing common passwords across many accounts) and MFA fatigue attacks (overwhelming users with repeated authentication requests to bypass multi-factor protection). The group claimed this gave them access to employee information at both firms.
The alleged data, according to both companies' investigations, was limited in scope and years old. HCLTech's investigation revealed that data allegedly exposed was limited and dated to several years prior, with no indication of current system compromise.
What Did the Investigations Find?
Both HCLTech and TCS conducted independent investigations and reached the same conclusion: no evidence of a breach of their systems or customer data. HCLTech found no impact on client engagements, and TCS similarly found no evidence that customer data, customer systems, or operational systems were affected.
The employee information that the hacker group referenced was older than researchers would expect to see in an active compromise. TCS disclosed that the information in the threat alerts was more than four years old and limited to basic employee data. The gap between the alleged data age and current operations suggested no ongoing system access.
What Safeguards Are in Place?
Both firms have maintained active defenses against the attack methods the hacker group claimed to have used. TCS stated it had maintained strong safeguards against password spraying and MFA fatigue attacks for over two years prior to the alleged incident, meaning protective measures were already deployed before the claims surfaced.
These safeguards are standard for IT services firms that handle sensitive customer systems. The presence of these defenses, combined with the age of the alleged data, made it implausible that a breach had recently occurred or succeeded at the scale claimed.
What Does This Mean for Customers and Employees?
Customers of both firms have no evidence that their data or systems were compromised. Neither TCS nor HCLTech found evidence that customer data or client engagements were affected.
This matters because both companies serve as IT services providers to other organizations—a role that requires high trust around system security. For employees at both firms, the findings suggest that if any data exposure occurred, it was limited to years-old information and did not include current credentials or access tokens. The investigation provides concrete evidence disputing the hacker group's public claims rather than simply denying them.
What Are the Limits of These Clearances?
An investigation by the company being accused, even an independent one, does not carry the same weight as a third-party forensic audit by an external cybersecurity firm. Both HCLTech and TCS disclosed their findings through press releases and stock exchange filings—official channels but not independently verified by outside parties.
The clearances do confirm that when each firm looked internally, they found no evidence of current compromise. That is a meaningful finding, but customers or employees wanting absolute certainty might reasonably request that these firms publish summaries of third-party forensic work if any was conducted.
Frequently Asked Questions
Did the hacker group successfully steal employee data from HCLTech or TCS?
According to both companies' investigations, no credible evidence of a breach was found. If any data existed from years prior, no current system compromise occurred.
Could my data be at risk if I work with or have accounts at these companies?
Both firms found no evidence that customer data, customer systems, or employee current credentials were compromised, making active risk from these specific claims minimal.
Why would the hacker group make false claims?
Threat actors sometimes publish claims to create reputational pressure, negotiate payoffs, or build credibility even without evidence. The companies' investigations contradict the claims, but reputation damage can occur regardless.
