
Tata Consultancy Services (TCS), India's largest software exporter, has flagged an alleged exposure of some employee data after receiving alerts about a potential leak. The company, however, moved quickly to reassure clients that customer data remains untouched.
In a statement, TCS said it investigated the claims and found no credible evidence of a breach. The alleged employee data, the firm noted, is limited and years old, suggesting the incident may not pose an immediate threat to its workforce or operations.
TCS acknowledged receiving alerts regarding the possible exposure of employee information. The Mumbai-headquartered firm stated that its security teams conducted a thorough review but could not substantiate the breach claims.
"We have not found any credible evidence of a breach," the company said, adding that customer data is not impacted. This clarification comes amid growing concerns over data security in India's IT sector, where firms handle sensitive information for global clients.
The development follows similar alerts faced by other Indian IT majors. HCLTech, another leading player, recently flagged an employee data leak claim but also said no breach occurred. The alleged data in both cases appears to be limited and outdated, easing immediate fears of large-scale compromise.
For TCS, which employs over 600,000 people worldwide, even a partial data exposure can raise regulatory and reputational questions. The company's swift response aims to preempt panic among its workforce and corporate clients who rely on its cybersecurity protocols.
TCS's assurance that customer data is safe is critical, given its role as a backbone for banking, retail, and healthcare systems across the globe. Analysts suggest that while the incident may prompt closer scrutiny, the lack of evidence of a breach could limit fallout.
The company has not disclosed the nature of the alerts or who issued them. Officials have not yet confirmed whether law enforcement or data protection authorities have been notified, though such steps are standard in similar cases.
TCS is likely to continue monitoring its systems and may issue further updates if new information emerges. The episode underscores the persistent threat of cyber incidents, even for firms with robust security frameworks.
Observers will watch whether regulators, such as India's Data Protection Board, seek a formal explanation. For now, TCS's message is clear: employee data concerns are being addressed, but the business remains unaffected.