HCLTech Refutes Cyberattack Claims, Clarifying Alleged Leaked Employee Data Is Dated
In response to the recent cyber threats targeting its security, Indian software and IT services firm HCLTech has stated that the data of the company that is available on dark web forums seems to be outdated. In a stock exchange filing, the technology company based in Noida, India, has reassured its customers and investors that the core infrastructure of its organization is completely safe and is not at all compromised.
The disclosure comes after the recent posting by an unknown threat actor of a database on a dark web forum, where he said that the database contained personal information of over 250,000 employees of HCLTech, including the name of the person, corporate email ID, designation, phone number, office location details, and service account logs.
As per his claims, the data was extracted from the Microsoft Azure tenant environment through compromised administrative credentials. After conducting an internal review of the security of its organization, the company has stated that there seems to be no sign of compromise in its current live systems, and the data is indeed quite outdated.
The company stated that all the data of their clients remains intact, although the forensic team is still working on a complete investigation of the full extent of the leakage of the documents. This attack marks a trend of cybersecurity threats facing leading enterprise service providers in the region.
The Indian rival, IT services provider Tata Consultancy Services (TCS), revealed an alert on their compromised, four-year-old database of employees’ credentials, along with financial institutions such as Bank of Baroda experiencing targeted credential attacks. With cybercriminals using automated techniques to search for exposed credentials and legacy databases, leading enterprise IT companies face constant pressure.
In this case, the fast response of HCLTech shows how important proactive monitoring is to keep clients’ trust and isolate the legacy data exposure from the active operational environment.