HCLTech Says Allegedly Stolen Employee Data May Be Years Old, Denies Internal System Breach

HCL Technologies has responded to claims by a threat actor that the Indian IT major’s employee data was stolen and put up for sale on a dark web forum.

The company said its initial investigation suggests that the data in question may be limited and could be several years old. HCLTech also clarified that it has found no evidence of a breach of its internal systems or any compromise involving its client engagement systems.

Hacker Claims Data of Over 2.5 Lakh Employees Was Stolen

A threat actor reportedly claimed on a dark web forum that a dataset containing information related to more than 2.5 lakh HCLTech employees was available for sale.

According to the claim, the dataset allegedly includes employee names, email addresses, job titles, departments, phone numbers and physical addresses. It also reportedly contains employee and service account records.

The threat actor further claimed that the information was obtained from a Microsoft Azure tenant using compromised credentials.

A Microsoft Azure tenant is a dedicated cloud environment associated with a particular organisation. However, the authenticity of the alleged dataset and the claims made by the threat actor have not been independently verified.

The claims were first reported by Intel and Breaches, an X account that monitors activity on dark web forums.

HCLTech Says No Evidence of Internal Systems Being Breached

In an exchange filing on August 10, HCLTech said its preliminary investigation had not found evidence suggesting that its systems had been breached.

The company said the data referred to in the claims may be limited and could date back several years.

HCLTech also said there was no evidence that systems related to its client engagements had been compromised.

The company has started a further investigation into the matter and said it will disclose any material findings that emerge from the review.

Why the Incident Is Raising Cybersecurity Concerns

The claims involving HCLTech come at a time when Indian companies are facing increasing cybersecurity threats.

Large organisations hold extensive amounts of employee, customer and operational data, making them attractive targets for threat actors. Compromised credentials can also become an entry point for attackers attempting to access cloud-based environments.

The incident has also highlighted the importance of securing cloud accounts and monitoring access to sensitive organisational data.

TCS Also Reports Possible Employee Data Exposure

HCLTech’s disclosure comes shortly after a similar development involving Tata Consultancy Services (TCS).

TCS said on Monday that it had received alerts regarding the possible exposure of certain employee-related information. However, the company said there was no indication that customer data or systems had been affected.

According to TCS, the information referred to in the alerts appeared to be more than four years old and was limited to basic employee information.

The company did not provide further details about the source of the alerts.

TCS also said it had security safeguards in place for more than two years against the method allegedly used in the incident. The company stated that its operational systems had not been impacted and that its existing controls remained effective based on its current assessment.

Bank of Baroda Also Faced Security Incident

The latest developments come after Bank of Baroda confirmed a security incident last month involving unauthorised access to certain data.

The public sector bank said the incident involved the compromise of an employee’s email account. Threat actors were able to gain unauthorised access to certain information as a result.

These incidents underline the growing cybersecurity risks faced by large organisations, particularly as companies increasingly rely on cloud platforms, digital systems and artificial intelligence-based tools.

Investigation Into HCLTech Claims Continues

For now, HCLTech has not confirmed that its systems were breached. The company has maintained that its initial investigation indicates that the allegedly exposed data may be old and limited in nature.

The alleged dataset has also not been independently authenticated.

The company is continuing its investigation and has said that any material findings will be reported. Until that review is completed, the full nature and origin of the alleged data remain unclear.

Comments (0)
Add Comment