HCL Technologies stated that its initial investigation found no evidence of breaches in its systems or client environments, following claims by a hacker group of accessing employee-related data. The Economic Times reports that the company issued this clarification in a late-Monday filing to stock exchanges, shortly after Tata Consultancy Services (TCS) made a similar disclosure.

What did HCLTech say?

In its exchange filing, HCLTech said the data referenced in the hacker group’s claim “may be limited and dated to a few years back.” The company stated there is no evidence of a breach of its own systems or of any engagement with its clients’ systems.

HCLTech also stated it will continue investigating and will disclose any significant findings.

The clarification was issued after media reports that a hacker group claimed to have accessed certain employee information from HCLTech. The company has not identified the group or explained how the data was allegedly obtained.

The TCS parallel

HCLTech issued its statement one day after TCS, India’s largest IT services firm, reported receiving threat-intelligence alerts regarding potential exposure of employee information. TCS stated that its investigation found no credible evidence of a breach in its systems or customer environments. It also said the data involved was over four years old and limited to basic employee details.

TCS reported that the attacker claimed to use password spraying and multi-factor authentication (MFA) fatigue as attack methods, and confirmed it has safeguards in place against these techniques.

What remains unresolved

Neither company has confirmed the scope or details of the alleged data exposure, and both investigations are ongoing. They have not stated whether affected employees, regulators, or law enforcement have been notified. The hacker group’s claims have not been independently verified.

Broader context

Recent disclosures from HCLTech and TCS reflect a broader trend of credential-based attacks targeting large Indian IT services firms. Their scale and access to client systems make them appealing to attackers. In HCLTech’s case, the hacker reportedly accessed data from a Microsoft Azure tenant using compromised credentials, a method security researchers identify as a growing entry point for cloud attacks. The hackers allegedly accessed over 2,50,000 employee details including their names, email addresses, job titles and phone numbers. The physical addresses, and employee and service account records were also compromised. \

Earlier in 2023, HCLTech experienced a ransomware incident in an isolated cloud environment. TCS has faced questions about whether its network was used in the 2025 cyberattack on UK retailer Marks & Spencer.

Also read: