Menu
Browse

Cyber Incident Victim: Cognizant Technology Solutions

Date

Apr 2026

Location

United States of America

Status

Unknown

Updated

2026-08-23 21:01

Timeline
Occurred
Apr 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

Cognizant Technology Solutions notified individuals of a data breach, saying it has no reason to believe the compromised information was misused. The company offered affected persons identity‑theft protection through IDX, including credit and CyberScan monitoring, a one‑million‑dollar insurance reimbursement and recovery services. It advised monitoring accounts, placing fraud alerts or security freezes, and noted the right to obtain a police report under Massachusetts law. A threat‑actor group claimed responsibility on a dark‑web forum. Separately, a subsidiary breach earlier exposed about 3.4 million individuals’ data, possibly including protected health information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

Around April 21, 2026, Cognizant Technology Solutions experienced a data security breach that the company later disclosed to affected individuals. According to ClaimDepot, a threat actor group known as CoinbaseCartel claimed responsibility for the incident by posting on a dark web site hosted on the Tor network on April 15, 2026, stating that it had obtained data belonging to the organisation. Cognizant’s notification letter did not specify the number of people affected or the nature and volume of personal information involved, and the company said it had no reason to believe that the compromised information had been misused. The notice expressed regret over the incident but offered no further technical details about how the breach occurred or whether it resulted from an external cyberattack or unauthorised access. Earlier in 2026, Cognizant’s subsidiary TriZetto Provider Solutions (TPS) reported a separate data breach that exposed sensitive information of approximately 3.4 million individuals, with a filing to the Office of the Maine Attorney General indicating that the incident may have included protected health information.

Cyber Incident Image

In response to the breach, Cognizant offered affected individuals identity theft protection services through IDX for a period of 24 months, which included credit and CyberScan monitoring, a $1 million insurance reimbursement policy and fully managed identity theft recovery services. The company advised recipients to monitor their account statements and credit reports regularly and to remain alert for any signs of suspicious activity. It also outlined specific steps that individuals could take, such as placing fraud alerts or security freezes on their credit files with the major credit reporting agencies. Cognizant noted that, under United States federal law, consumers cannot be charged to place, lift or remove a security freeze on their credit. Additionally, the notice informed affected individuals of their right to obtain a police report relating to the incident under Massachusetts law and to file a police report if they later become victims of identity theft.

Cognizant’s notice did not disclose the method by which the breach was carried out, nor did it specify whether the incident involved an external cyberattack or unauthorised internal access, and it did not identify the categories of personal information that may have been exposed. The company did not provide further details in response to media inquiries, as an email sent to Cognizant remained unanswered by the time of publication. While the notification described the remedial measures being offered, it left open questions about the scope of the data compromised and the potential long‑term consequences for the individuals whose information was involved.

Sources
Sources available to members
1 source