2026 Tata Consultancy Services (TCS) — TheHatman Azure claim (~800K); NSE filing denies systems breach
Data compromised
Actor-claimed ~800,000+ Azure employee-directory records. TCS: details appear at least four years old and include only basic employee information; no credible evidence of a current systems breach. Still labeled unverified as to actor count.
Technical writeup
Unverified forum sale with company denial — August 17, 2026 BleepingComputer roundup of TheHatman’s claimed 3.64 million Azure directory records across Fortune 500 tenants. TCS is listed at ~800,000. In a National Stock Exchange / BSE filing, Tata said it found no credible evidence of a breach of TCS systems or customer environments; advertised details appear at least four years old and include only basic employee information. The attacker claimed password spray and MFA fatigue; TCS said it has had strong safeguards against those techniques for more than two years and that reviewed defenses remain effective. Hudson Rock still assessed samples as consistent with Entra-style exports. BreachHistory keeps recordsAffected 800000 as the actor figure, companyConfirmed false, and records the NSE denial.
Root cause
Unverified TheHatman forum sale of an alleged Azure tenant employee dump; TCS NSE/BSE filing says no credible evidence of a TCS or customer-environment breach and data appears years old
References
- https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
- https://www.bseindia.com/xml-data/corpfiling/AttachLive/ac9edbea-ea43-4c0a-beb8-5239bcd03ec9.pdf
- https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/