A threat actor is claiming to have stolen internal employee data from HCL Technologies (HCLTech) and is offering the alleged database for sale on a cybercrime forum. The claims have not been independently verified, and HCLTech had not issued any public statement regarding the alleged incident at the time of publication.
According to the forum post, the seller claims the data was obtained directly from an Azure tenant using compromised credentials. No technical evidence was provided to substantiate the claim beyond a downloadable sample dataset that the seller says contains a subset of the records.
Alleged employee database
The threat actor claims the dataset contains more than 250,000 records associated with HCLTech employees and tenant accounts.
According to the listing, the allegedly exposed information includes:
- Full names
- Email addresses
- Job titles
- Departments
- Phone numbers
- Addresses
- Employee accounts
- Service accounts
- Other Azure tenant account records
The seller advertises the database to interested buyers and also claims to possess additional corporate datasets from other organizations.
Azure compromise claim remains unverified
The forum post alleges the information was extracted from an HCLTech Azure tenant using compromised credentials. However, the seller did not publish forensic evidence, screenshots of the Azure environment, or other material that would independently confirm the claimed access.
About HCLTech
HCLTech is a global technology services and digital engineering company headquartered in India. The company provides cloud, AI, software engineering, cybersecurity, and IT outsourcing services to enterprise customers worldwide. It reported approximately $14.7 billion in revenue for fiscal year 2025.
No public confirmation
At the time of publication, HCLTech had not issued any public statement confirming a security incident related to the claims made in the forum post. The company’s recent public announcements do not reference any such breach.
Organizations whose employee directories are exposed can face increased risks of phishing, credential harvesting, business email compromise, and social engineering attacks, particularly if corporate account information is accurate.
BreachNews will update this article if HCLTech confirms or denies the alleged incident.











