Cognizant has notified customers of a data breach that occurred on April 21, 2026, potentially exposing sensitive personal information, including Social Security numbers. The IT services company says it currently has no evidence that the compromised information has been misused.
The company reportedly began notifying affected individuals in August, nearly four months after the incident. Cognizant has not publicly disclosed the number of people affected. A cyber-extortion group calling itself CoinbaseCartel has reportedly claimed responsibility.
Cognizant is offering affected individuals 24 months of credit and CyberScan monitoring, managed identity-theft recovery services and up to $1 million in identity-theft insurance reimbursement through IDX. Customers have also been advised that they can place security freezes on their credit reports.
The incident comes at a sensitive time for India's IT services industry, where questions around employee data, privileged access, third-party exposure and cybersecurity governance are receiving greater scrutiny.
The Bigger Risk Is Persistent Identity Exposure
The most concerning element is the potential exposure of Social Security numbers. Passwords and payment cards can be replaced, but permanent identity attributes can potentially be exploited long after a breach, making identity monitoring particularly important.
The reported four-month interval between the April incident and August notification also highlights a broader cybersecurity challenge: breach containment is only one part of incident response; detection, investigation and notification speed matter as well. However, the notification timeline alone does not establish when Cognizant first detected the incident or whether there was continuous exposure throughout that period.
For large IT services companies, the implications extend beyond their own employees and customers. They operate deeply inside client environments and frequently handle sensitive enterprise information, making identity governance, privileged-access management, continuous behavioral monitoring and Zero Trust controls increasingly critical.
The larger lesson is that cybersecurity is moving beyond protecting systems toward protecting persistent digital identities. Credit monitoring can help after information is compromised, but enterprises increasingly need controls capable of detecting abnormal identity behavior before stolen information becomes successful fraud.
The new security question is no longer simply, “Was data stolen?” It is: “Can stolen identity data be prevented from becoming a trusted identity?”
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




