800,000 TCS Employee Records on the Dark Web? What the Data Reveals

800,000 TCS Employee Records on the Dark Web? What the Data Reveals

A dark-web actor claims to have 8 lakh TCS employee records stolen from an Azure tenant. OBC traced the listing, examined a sample of 6,000 records and found a trove of employee information—including corporate emails, IDs, job titles and locations. But the evidence doesn’t prove a new breach. TCS says the data is at least four years old. Here’s what the sample actually tells us—and why old data can still be dangerous.

On August 10, Offbeat Concerns identified employee data allegedly linked to Tata Consultancy Services (TCS) for sale on a dark web leak forum. The threat actor under the alias ‘TheHatman’ claimed in a post shared on a dark web leak forum that around 8,00,000 records of employee information from TCS were directly accessed using compromised credentials. TCS stated that, although they received threat intelligence alerts about a possible data leak involving employee data, none of the customer data or systems was impacted.

This OSINT investigation examines the leak forum post, threat actor, and the sample data allegedly associated with the leak.

What OBC observed?

On August 9, the threat actor who goes by the name ‘TheHatman’ shared a post in a dark web forum inviting potential buyers, claiming that 8,00,000 records of TCS employee data, directly downloaded from an Azure tenant using leaked credentials, were up for sale.

Screenshot of a post shared on the dark web forum.

An Azure tenant is a dedicated instance of Microsoft’s cloud identity and access environment associated with an organisation. It contains identities such as employees, groups, applications and service accounts, along with the permissions and access controls used to manage an organisation’s cloud resources.

The post titled ‘TCS (TATA CONSULTANCY) 800K+ AZURE DUMP | FULL NAME, EMAIL, TITLE, PHONE, ADDRESS’ claims that the leaked data dump contains key employee data, including full name, official email and Employee ID.

What does the sample data say?

We noted that the post included download links to a 6,000-record sample allegedly taken from the leaked dump. The analysis of the sample data revealed that it included employee names, corporate email addresses, employee IDs, job titles, departments, cities, office locations and, in a smaller number of cases, telephone numbers, mobile numbers and postal addresses.

Screenshot of the sample data (redacted).

The sample data included employee information linked to TCS offices in Chennai, Bengaluru, Kolkata, Hyderabad, Pune, Mumbai, Gurgaon, Noida, and Kochi, as well as entries for overseas locations. However, the dataset was not entirely clean. Our analysis identified duplicate employee IDs, blank employee IDs and inconsistencies in fields such as city, country and office location. Some records also used different corporate email domains, suggesting that the sample may have been compiled from multiple organisational systems or directories.

The image shows features of the sample data.

The dump also included key roles across cybersecurity, cloud infrastructure, system and database administration, software engineering, project management and consulting. It contained titles linked to AWS, security analysis, infrastructure services and BFSI operations, offering a glimpse into the technical and business functions represented in the dataset.

However, the sample data alone does not establish when the records were obtained. It is therefore not possible to determine solely from the sample whether the data originated from an earlier breach or represents a more recent leak.

What do we know about the threat actor ‘TheHatman’?

The account ‘TheHatman’ was registered on the dark web leak forum on March 31, 2026, and has so far shared five posts, including one posted on August 7 that claimed to sell 2,50,000 records of leaked data associated with HCL Technologies.

The image shows the threat actor’s profile (redacted).

Similar to the TCS dump, the HCL dump was also advertised by TheHatman as an alleged 250K+ Azure dump, with the listing claiming to contain employee names, corporate email addresses, job titles, departments, telephone numbers and physical addresses. The listing also claimed that the data included employee and service account records, although the available evidence does not independently establish the dataset’s source or authenticity.

What does TCS say?

In an official statement, TCS said that although it received threat intelligence alerts about a possible data leak involving employee data, none of the customer data or systems was impacted. They also indicated that the leaked data, which was on sale on a dark web portal, appeared to be at least 4 years old.

Why is old data still dangerous?

Employee details on this scale could provide enough context to craft convincing, targeted phishing messages. An attacker can use such information to impersonate HR teams, IT support or senior employees, or to target people in specific departments. 

Old data can also be combined with newer information from social media, public profiles, or other data leaks to build updated employee profiles. This means that while the dataset may not represent a recent breach, its continued circulation could still increase the risk of targeted phishing, impersonation and social-engineering attacks.

Our analysis found that the threat actor was advertising TCS-associated employee data as a recent 8,00,000+ record Azure dump. However, TCS has indicated that the data circulating on a dark web forum was four years old and that no cyber threat has recently affected the organisation. While the claim of a recent breach remains unsubstantiated, the continued circulation of such data can still pose risks of more targeted, sophisticated cyberattacks.

Sujith A

Sujith A

Open Source Intelligence Researcher and Mis/Disinformation tracker. Passionate about investigations and a big fan of Sherlock Holmes.

View all posts by Sujith A
Share Email
Top