When attackers log in: Why employee identities are becoming IT’s weakest link

/ 4 min read
AI Hub

As attackers ‘log in rather than break in’, stolen employee credentials are emerging as the fastest route into India’s IT giants and their global client systems

Getty Images
Credits: Getty Images

For India’s large IT services companies, the biggest cyber threat may no longer be someone trying to break into their systems from the outside. Increasingly, attackers are trying to get in using something that already has access--an employee’s identity.

ADVERTISEMENT

Recent alerts involving Tata Consultancy Services (TCS) and HCLTech have brought the issue into focus. TCS said on August 10 that it had received alerts about the possible exposure of some employee information. The company said the data appeared to be more than four years old and limited to basic employee information, with no indication that customer data, customer systems or its operational systems had been affected. 

HCLTech also said an initial investigation into a hacker claim found that the data may have been limited and several years old. The company said there was no evidence of a breach of its systems and no indication that any client engagement had been affected. 

ADVERTISEMENT

The Indian Computer Emergency Response Team (CERT-In) issued a critical advisory on August 7 warning of a rise in attacks targeting Microsoft 365 accounts. These attacks include password spraying, device-code phishing, stolen session tokens and the misuse of authentication systems. 

The shift is important because a stolen employee login can give an attacker access without having to break through a company’s systems in the traditional sense. “Compromised identity is now one of the main routes into the enterprise,” said Rohan Vaidya, Area Vice President - India & SAARC - Identity Security at Palo Alto Networks.

According to Palo Alto Networks’ 2026 Global Incident Response Report, identity-based techniques accounted for 65% of initial access, while identity weaknesses played a material role in nearly 90% of investigations, Vaidya said. Once attackers get a credential, they can check what the employee has access to, move across systems, try to gain higher privileges or steal session tokens. For large IT services companies, the risk is even higher because employees can have access to several client environments. “The biggest risk is a one-to-many compromise,” Vaidya said.

An employee working for an IT services company may have access to a customer’s systems, cloud platforms or other tools, and if that account is compromised, the attacker may be able to use the same identity to reach multiple systems. This is why simply changing passwords or conducting periodic security checks is no longer enough.

Recommended Stories

“Attackers increasingly want to operate as the employee, not merely possess the employee’s password,” Vaidya said. Attackers can use phishing, voice calls, help-desk manipulation, stolen sessions and other methods to make their activity look like normal employee behaviour. This makes identity-based attacks harder to detect because the login itself may appear legitimate.

Why IT services companies face a bigger risk

The risk is particularly high for IT services companies because they manage technology and data for customers across different countries and industries. Varun Grover, Business Unit Head at mFilterIt, said employee credentials have become “one of the weakest links in enterprise security”, particularly for large IT companies managing sensitive data and infrastructure for clients across the globe.

ADVERTISEMENT

“A single compromised login can cascade into a multi-client breach,” Grover said. A compromised employee account does not automatically mean that customer systems have been breached. But the level of access attached to that account can determine how far an attack can spread.

This is also why companies are increasingly looking at identity security as part of their overall cyber security strategy. Harish Kumar, CEO of Quick Heal Technologies, said the recent alerts around possible data exposure at large IT services companies show that even mature organisations are not immune to attacks.

Most Powerful Women In Business 2026
View Full List >

“identity has become the new perimeter, and compromised employee credentials are among the most reliable entry points for adversaries,” Kumar said. For IT companies, he said, one compromised credential can create supply-chain exposure, contractual risk and damage to client trust.

The problem with permanent access

One of the biggest weaknesses is giving employees more access than they need, and leaving that access active for too long. Vaidya said companies should move away from treating identity as something that is checked only when an employee logs in. Instead, access should be reviewed continuously based on factors such as the device being used, location, login behaviour and session activity.

He also pointed to the growing number of machine identities. According to Palo Alto Networks, machine identities now outnumber human identities globally by 109 to 1, adding another layer to the identity security problem.

“Client access should be isolated and individually attributable, with privileges granted only for a specific system, purpose and duration, then removed automatically,” Vaidya said.

ADVERTISEMENT

The recent CERT-In warning shows why this approach is becoming more important. Attackers are increasingly using legitimate Microsoft authentication processes to gain access, rather than relying only on malware. CERT-In warned that attackers can even register unauthorised devices in Microsoft Entra ID after compromising an account, allowing them to maintain access after a password is changed. 

What companies need to change

For enterprises, the answer is not one security product or another layer of passwords. It requires several controls working together. Kumar called for a “Defense in Depth” approach, including employee awareness, regular vulnerability checks, Zero Trust Network Access, phishing-resistant multi-factor authentication, endpoint security and stronger data protection.

ADVERTISEMENT

Companies also need to know when their employee credentials appear in leaked databases or on the dark web. Grover said organisations need real-time monitoring for leaked or dark-web-traded credentials, along with checks for unusual login locations, device changes and activity outside normal working hours.

For employees, some of the basic safeguards remain important, using different passwords, avoiding corporate credentials on personal platforms, being careful with unexpected login requests and reporting suspicious activity quickly. Kumar said the rise in identity misuse, OAuth abuse and credential-led intrusions shows that attackers are increasingly choosing to “log in rather than break in”.

ADVERTISEMENT

For India’s IT services industry, the lesson from the latest cyber alerts is therefore that the employee account itself has become a critical security layer.

NEXT STORY