HCLTech has disputed a threat actor’s claim that more than 250,000 employee and tenant-account records were stolen and offered for sale, saying its initial investigation found no evidence of a breach of company systems or any impact on client engagements. The company said the exposed information, if genuine, appears to be limited and several years old, and it filed a clarification with India’s National Stock Exchange and Bombay Stock Exchange while continuing its investigation.
The sale listing, posted by an actor using the alias “TheHatman,” advertised an alleged internal database supposedly obtained from an Azure tenant with compromised credentials and included a sample of roughly 7,500 records. Reported fields included names, corporate email addresses, job titles, departments, phone numbers, physical addresses, and account information, but available evidence only confirms that data is being marketed online, not that HCLTech was breached, that the dataset is authentic, or that Microsoft Azure itself was compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
HCLTech filed a formal clarification with the National Stock Exchange and Bombay Stock Exchange stating its initial investigation found the referenced data may be limited and several years old. The company said it found no evidence of a breach to its systems or any impact on client engagements and that it was continuing to investigate.
A threat actor using the alias "TheHatman" advertised an alleged internal HCLTech employee and tenant-account database for sale, claiming it was obtained from an Azure tenant using compromised credentials. The listing claimed more than 250,000 records and offered a sample of about 7,500 records.
HCLTech publicly reported having 223,000 employees as of June 30, 2026. This figure was later cited to note that the claimed 250,000-record dataset exceeded the company's stated employee headcount.
HCLTech disclosed a separate ransomware incident affecting an isolated cloud environment associated with one project. The reference notes there is no evidence linking that 2023 event to the 2026 alleged employee-data exposure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.