Threat Intelligence Brief
Curated summary with source attribution
Source: money.rediff.com
Threat Risk: Low
Victim: Tata Consultancy Services
Incident: Alleged leak of basic employee information via password spraying and MFA fatigue.
Impact: Limited exposure of legacy employee data with no reported impact on customers or operational systems.
Attacker: Unidentified threat actor
Analysis: The incident involves the alleged exposure of basic employee data that is over four years old. The attacker claims to have utilized password spraying and MFA fatigue to gain access, though TCS maintains that its current security controls are effective.
Recommendations: Transition to phishing-resistant MFA to mitigate MFA fatigue attacks; Implement robust account lockout policies to thwart password spraying; Enforce strict data retention policies to minimize the footprint of legacy data
Source: Rediff Moneynews
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-10 15:52 UTC
Alleged leak of basic employee data through authentication attacks. Exposure of outdated employee information with no reported impact on customer systems. The incident involves a claim that basic employee data was leaked using password spraying and MFA fatigue techniques. TCS indicates the data is outdated by over four years and does not affect current operations or customer systems. This serves as a reminder that legacy data remains a target even after security controls are updated.
Corroborating source: m.rediff.com