ThreatPaper
Assessed, Not Confirmed

TCS found no breach; the leaked data is over four years old

Assessment

This is TCS's own first-party assessment in its Regulation 30 exchange filing TCS/SE/72/2026-27 of 10 August 2026: it 'has not found any credible evidence of a breach of TCS systems or customer environments' and the referenced information 'appears to be more than four years old and limited to basic employee information'. It is a company statement, not independently verified; no regulator or third party has dated the data or confirmed TCS's finding, and Hudson Rock assessed samples as likely authentic without dating them. It is recorded because it is widely repeated as settled fact rather than as the company's own, unverified conclusion.

Where this claim appeared

Tata Consultancy Services (NSE/BSE Regulation 30 filing) · 2026-08-10

https://www.bseindia.com/xml-data/corpfiling/AttachHis/ac9edbea-ea43-4c0a-beb8-5239bcd03ec9.pdf

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

TCS employee-directory leak claim: 800,000 records advertised by 'TheHatman', company finds no breach

Think this assessment is wrong? Report an error.