Loading...

Why old employee data is becoming a new cybersecurity headache for companies

Why old employee data is becoming a new cybersecurity headache for companies
Loading...

Two of India’s largest technology services companies are confronting an unusual cybersecurity problem this week: information linked to their employees has allegedly surfaced outside their organisations, even as investigations have so far found no evidence of a fresh compromise of their corporate systems.

Tata Consultancy Services (TCS) on Monday said it had received threat-intelligence alerts alleging possible exposure of certain employee-related information. The company said the information appeared to be more than four years old and limited to basic employee data, with no indication that customer data or operational systems had been affected.

HCLTech subsequently responded to claims by a hacker group that it had accessed employee data. The IT services company said its initial investigation found no evidence of a compromise of its systems or impact on client engagements, while the information claimed to have been exposed “may be limited and dated to a few years back”. Its investigation is continuing.

Loading...

The two cases put the spotlight on a less visible cybersecurity challenge facing enterprises: data can outlive the systems, employees and security controls that originally generated it.

Employee information collected years ago may remain scattered across HR systems, recruitment platforms, payroll processors, background-verification firms, insurers, former vendors and archived databases. Once some of that information escapes into the cybercrime ecosystem, it can be copied, combined with other datasets and resurface years later.

For chief information officers (CIOs) and chief information security officers (CISOs), this creates a difficult problem. An organisation may secure its current infrastructure but remain exposed through information and identities belonging to people who work—or once worked—there.

Old data, new attack surface

Loading...

The value of leaked information does not necessarily disappear because it is old. Passwords may have changed and former employees’ accounts may have been disabled, but names, corporate email addresses, phone numbers, designations and reporting relationships can remain useful for years.

This is also why corporate information appearing on the dark web does not by itself establish that an organisation has suffered a fresh breach. Cybercriminals can aggregate, repackage and recirculate previously stolen information.

“Attackers exploit credentials rather than breaking into the systems through traditional methods,” Dor Liniado, chief information security officer at CyberArk, told TechCircle last year, pointing to the increasing complexity of human identities and privileges across organisations.

Loading...

But there is another risk: former employees’ access may not disappear as neatly as organisations assume.

“During their tenure, employees accumulate access across dozens of systems—in-house applications, SaaS tools, shared service accounts. When they leave, that access rarely gets revoked all at once,” said CEO & Chief FieldCISO at FieldCISO Advisory Services, a specialised cybersecurity advisory firm. Lack of central visibility, inconsistent offboarding or business processes dependent on an existing account can leave access behind, he added.

For attackers, such identities can be more attractive than exploiting a software vulnerability.

Loading...

“A dormant but valid identity is easier to weaponise than a zero-day, because nobody’s looking at it—it doesn’t trigger an intrusion alert, it just looks like a login,” Bhajanka said. “The operational value of that data decays over time; the liability doesn’t.”

The external employee-data footprint can be equally sprawling. Information passes through recruitment and background-verification agencies, payroll providers, insurers and multiple software-as-a-service platforms. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, highlighting the growing exposure beyond organisations’ immediate infrastructure.

Mandy Andress, global CISO at Elastic, believes that third-party risk now extends from traditional business vendors to the software supply chain. Organisations need rigorous risk analysis before onboarding vendors and should design integrations to limit the “blast radius” of a compromise, she said.

When yesterday’s data becomes tomorrow’s attack

Loading...

The greater danger arises when old employee information becomes reconnaissance for a new attack.

A database containing a person’s name, designation, corporate email and mobile number may not appear highly sensitive. Together, however, those details can tell an attacker whom to contact, whom to impersonate and what communication might appear credible.

Employees could receive fake password-reset requests containing accurate workplace information, while finance executives could face impersonation attempts. Attackers can pose as recruiters, colleagues, IT administrators or senior executives.

Loading...

Artificial intelligence potentially raises the stakes further by allowing attackers to combine fragmented information and generate personalised phishing and social-engineering attempts at scale. “What once unfolded over days now happens in minutes—or seconds,” Andress mentioned, pointing to threat actors’ growing use of AI.

This is why enterprise cybersecurity is increasingly moving away from the notion of a clearly defined corporate perimeter.

“Identity is now the operational perimeter,” Subhalakshmi Ganapathy, chief IT security evangelist at ManageEngine, the security division of Zoho Corp., said in an earlier interview. She argued that enterprises need identity-centric security alongside data classification, retention controls and deletion processes as digital environments expand.

The identity problem could become more complicated as enterprises deploy AI agents capable of accessing applications and corporate data. Bhajanka warned that as AI agents increasingly operate like “headless employees”, stale or retired agents that retain access to enterprise data could provide attackers another window of opportunity.

That means offboarding may increasingly apply not only to people, but also to machines.

For CIOs and CISOs, the response has to extend beyond protecting networks and databases. Enterprises need tighter data-retention and deletion policies, visibility into employee information held by third parties, continuous monitoring for leaked credentials, removal of dormant accounts and rigorous revocation of access when employees—or AI agents—leave a role.

The TCS and HCLTech cases underline the larger problem. Cybersecurity teams can patch vulnerabilities, replace software and rotate passwords. What they cannot easily patch is information once it has escaped.

In an underground economy where stolen datasets can be copied, combined and reused for years, yesterday’s employee records can become the raw material for tomorrow’s cyberattack.


Sign up for Newsletter

Select your Newsletter frequency