TCS, HCLTech and Hexaware Technologies are pushing back against dark-web claims that employee data was stolen from their cloud environments. All three say their checks found no reliable evidence that core systems or customer environments were breached.
A threat actor using the name “TheHatman” has advertised employee-directory datasets said to come from nine large companies. Hudson Rock’s analysis said samples appeared highly likely to be authentic, though researchers could not confirm exactly how the data was obtained. That leaves a gap between what researchers see in the files and what companies have found internally.
What Did The Hacker Claim About TCS, HCLTech And Hexaware?
The alleged campaign surfaced through dark-web posts beginning around July 31. The seller claimed access to roughly 3.64 million records across companies including McDonald’s, Vodafone, Kyndryl, Gap, InterContinental Hotels Group, and Wyndham Hotels, along with the three Indian IT firms.
According to BleepingComputer’s report on the alleged Azure data theft, the biggest Indian dataset advertised was linked to TCS, with more than 800,000 records. HCLTech was listed with over 250,000 records, while Hexaware was linked to more than 20,000. Those row counts should not automatically be read as current employees affected. Former workers, contractors and service accounts can also sit inside enterprise directories.
The reported fields included:
- Full names, corporate email addresses and employee IDs
- Job titles, departments, office details and reporting lines
- Phone numbers and, in some samples, physical addresses
- Group memberships, service accounts and privileged administrator names
Moneycontrol’s official X post also highlighted the three companies’ denials and the concerns being raised by cyber researchers.
What Did Cyber Researchers Actually Find In The Samples?
Hudson Rock said the samples contained corporate domains, tenant-specific Microsoft structures and field names matching typical Azure or Microsoft Entra directory exports. Researchers also reportedly found service accounts and names linked to Global Administrator roles. That is more useful to criminals than a plain contact list.
Sunny Nehra, founder of Secure Your Hacks, told Moneycontrol in its August 20 report that the structure he reviewed was consistent with genuine Azure or Entra exports. Still, authentic-looking records do not by themselves prove that a company’s current production systems were freshly breached.
A detailed company directory can help an attacker identify finance staff, senior managers, helpdesk workers or administrators, then build convincing spear-phishing and impersonation attempts. Reporting lines can also make fake approval chains easier to craft.
Was Microsoft Azure Itself Hacked?
There is no public evidence so far of a broad Azure zero-day behind the claims. Hudson Rock said possible routes include stolen credentials, infostealer malware, phishing, session-cookie theft, weak MFA controls or third-party applications with excessive permissions.
An attacker using a valid stolen login can sometimes extract directory information without exploiting the cloud platform itself.
What Have TCS, HCLTech And Hexaware Said?
TCS told exchanges on August 10 that it had received threat-intelligence alerts but found no credible evidence of a breach of TCS systems or customer environments. It said the referenced information appeared to be more than four years old and limited to basic employee data. Customer data and operational systems, it added, were not impacted.
HCLTech followed with a similar clarification, saying its initial review suggested the data could be limited and several years old. The company said it found no evidence of a breach of its systems or client engagements and was continuing its investigation. The Indian Express report on HCLTech’s clarification also noted that the authenticity of the hacker’s full claim had not been independently established.
Hexaware issued its response on August 19. It said its internal investigation found no reliable evidence of a breach of company systems or customer environments. It also described the material being discussed as outdated, non-sensitive corporate directory information.
Cyber experts remain cautious. Moneycontrol quoted Agnidipta Sarkar of ColorTokens as saying that “no evidence” reflects what an organisation can currently see in logs and threat feeds, rather than automatically closing the issue.
Why Can Old Employee Directory Data Still Create Risk?
Old information can lose value, but it does not become harmless simply because it is dated. Corporate email formats may remain unchanged. Former reporting structures can point attackers towards teams and roles. Service-account names can provide clues about internal systems.
For employees, the more likely follow-on threat is targeted phishing rather than immediate financial theft. Attackers can use accurate job titles, manager names and company language to make fake password-reset messages or helpdesk calls look convincing. Researchers have specifically warned about spear-phishing, helpdesk impersonation and privilege mapping.
For investors and enterprise clients, fresh disclosures, confirmed misuse of the data, unusual login campaigns or evidence of customer impact would change the picture quickly. Until then, the breach claims remain allegations supported by researcher-reviewed samples, while the three companies continue to deny a current compromise.
FAQS
Did TCS confirm a data breach?
No. TCS said it found no credible evidence that its systems or customer environments were breached.
How many HCLTech records were allegedly exposed?
The hacker advertised more than 250,000 HCLTech-related records, according to cyber researchers tracking the posts.
What data was allegedly taken from Hexaware?
Reported fields included employee names, emails, IDs, phone numbers, addresses and other directory-related information.
Can old employee data still be dangerous?
Yes. Attackers can reuse old directory details for phishing, impersonation, privilege mapping and social engineering.
Was Microsoft Azure confirmed to have a vulnerability?
No. Researchers currently suspect compromised credentials or identity-related access rather than a confirmed Azure flaw.
More Technology & Cybersecurity News
Google Offers Indian Students One Year Of AI Plus Free With Gemini Omni And 400GB Storage
ISRO To Resume Launches With GISAT-1A After Seven-Month Pause: Why Has India’s Calendar Been Quiet?


