IT major Cognizant has notified its customers about a data breach incident that took place on April 21 this year in a letter. However, the New Jersey-based company, said it found no credible evidence that the data had been misused.
The breach was reported nearly four months later on August 18 to the Massachusetts Office of Consumer Affairs and Business Regulation after which the IT firm sent written notices to the impacted individuals via an e-mail.
The personal information, reportedly exposed in the data leak, contained social security numbers.
“While we have no reason to believe that your information was misused, we thought it prudent to make this notification. We deeply regret this incident and any inconvenience to you and recommend you contact the number below for more information,” the letter stated. “Under Massachusetts law, you have the right to obtain any police report filed in regard to this incident. If you are the victim of identity theft, you also have the right to file a police report and obtain a copy of it.”
Claim Depot, a firm that helps consumers file claims for class action lawsuits and corporate data breaches, revealed that a hacker group called CoinbaseCartel had claimed responsibility for the incident.
The company added that the affected users could also place a security freeze on their credit reports for zero charges, which would disallow a credit reporting agency from releasing any details about a consumer’s credit report without written authorisation. Cognizant has also offered identity theft protection services through data security expert IDX. The list of services provided by IDX include 24 months of credit and CyberScan monitoring, a $1 million insurance reimbursement policy and fully managed ID theft recovery services. “With this protection, IDX will help you resolve issues if your identity is compromised,” the letter said.
Cognizant reassured that while there was no proof that any details had been misused, it encouraged the users to “take full advantage of the service offering.”
Weeks prior to this, its peers from the IT services industry, including Tata Consultancy Services (TCS), HCLTech and Hexaware all flagged similar instances of data breaches involving employees. However, all the companies dismissed these reports clarifying that the incidents were dated and didn’t comprise any sensitive data.
