Tata Consultancy Services flagged possible employee data exposure on August 10, 2026, after receiving threat intelligence alerts. India’s largest IT firm said the alerts concerned older employee information, while customer data remained unaffected.
TCS said the alerts pointed to basic employee details and showed no evidence of compromised operational systems. The company continues monitoring its environment while reviewing the claims through existing cybersecurity controls.
The alleged TCS employee data exposure involves information that appears more than four years old, according to the company. TCS did not disclose who issued the alerts or when the information surfaced online.
Reports linked the claims to alleged listings of employee records on online forums. The company has not confirmed the authenticity or source of those records.
TCS said the information referenced in the alerts remains limited to basic employee data. The company also said its customer environments show no signs of compromise from the reported incident. Its operational systems also continue to function without any reported impact.
The IT major said safeguards against the reported attack method have operated for more than two years. TCS added that its current review shows those controls remain effective against such threats.
"Based on the current review, these controls remain effective," TCS said in its statement. The company added that it continues to monitor the environment closely for emerging risks.
The disclosure highlights growing cybersecurity pressure on major Indian technology companies handling large volumes of sensitive information. For TCS, the immediate concern centers on employee records rather than customer systems or services.
The company’s ongoing review could clarify whether the alleged employee data exposure represents an actual security incident. TCS has not reported any impact on customer operations or service delivery so far.
Also Read: TCS Share Price Jumps as IT Stocks Stage a Sharp Comeback