IT companies play down data breach incidents; experts not convinced

Indian IT firms have downplayed recent data breach reports, but cybersecurity experts say the bigger risks could lie in client trust, contractual exposure, regulatory scrutiny and reputation

cyber fraud
Experts argue the technical severity of the breaches is less important than the commercial exposure they create. Image: Shutter stock
Avik Das Bengaluru
4 min read Last Updated : Aug 24 2026 | 7:11 PM IST
Several major Indian information technology (IT) companies have downplayed data breaches disclosed this month, but for an industry that runs a large part of the world’s technology landscape, the commercial damage may matter more than the technical one, say experts.
 
The denials and statements came following a report by Tel Aviv-headquartered Israeli cybercrime intelligence firm Hudson Rock, which said a hacker claimed to have sourced the companies’ Azure tenants that stored critical data, including the full names, employee IDs, email addresses, phone numbers, and addresses of employees. The report showed more than 800,000 records of Tata Consultancy Services (TCS), 250,000 of HCLTech, and 20,000 of Hexaware. The other companies include McDonald’s, Kyndryl, and Gap.
 
Throughout this month, TCS, HCLTech, and Hexaware issued statements to the exchanges saying that even if certain employee information may have been breached, the information was old and limited. Cognizant went a step further last week; it acknowledged a breach on April 21, notified affected individuals, and offered them identity theft protection for 24 months, which includes a $1 million insurance reimbursement policy and fully managed identity theft recovery services.
 
Sunny Nehra, founder of cybersecurity firm Secure Your Hacks, said the hacks did take place, as the leaked material is consistent with genuine Azure or Entra exports. “The access event is real even if the companies dispute its timing and depth,” he said.
 
Experts argue that the technical severity of the breaches is less important than the commercial exposure they create.
 
“Technically, it is not severe. But commercially, it can be quite serious. India runs a large part of the world’s back office, and trust is the actual product we sell. One thing I would gently disagree with is the argument that the data is old. A password ages. But the organisation chart does not. A four-year-old reporting line is still a working map and a live target,” said Srinivas L, joint managing director and joint chief executive officer (CEO) of 63SATS Cybertech.
 
Nehra points to a legal dimension behind the companies’ emphasis on the data’s age. “From a Digital Personal Data Protection (DPDP) Act perspective, this distinction (old and new) becomes especially useful for the companies. Employee directory data is clearly personal data under the Act. By characterising the incident as an older event that occurred well before the relevant DPDP provisions became fully operative, the companies can argue that the strict new notification timelines and penalty exposure do not automatically apply. That is a legitimate legal distinction, but it is also a convenient one.”
 
Experts say the companies' reluctance to confirm breaches comes down to risk, reputation, and liability management. Acknowledging a breach immediately invites questions from clients and can trigger contractual notice requirements, insurance notifications, and regulatory scrutiny.
 
Ranjeeth Bellary, partner, forensic and integrity services, EY, explains that new-age attackers have moved on from ransomware to identity theft and supply-chain attacks, thus increasing the impact radius. “Bigger attacks always compromise humans than systems,” he said.
 
This shift, experts say, demands a different posture from IT firms than the one they have relied on so far. “This is a people-dependent industry and with artificial intelligence (AI), it will get increasingly difficult to fight the new battle with old technology. You need vulnerability management, threat exposure management, threat detection, configuration management to run 24x7 and not in cycles as was the case earlier,” explained Pankit Desai, cofounder and CEO of cybersecurity company Sequretek.
 
While in the age of AI no company is immune to attacks and it is impossible to prevent all of them, cybersecurity experts call for more prevention mechanisms rather than relying on resilience.
   

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Premium stories handpicked daily by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :IT firmsIT companiesData breach

First Published: Aug 24 2026 | 3:07 PM IST

Next Story