Cyber Incident Victim: Cognizant Technology Solutions
Timeline
Summary
Cognizant Technology Solutions notified individuals of a data breach, saying it has no reason to believe the compromised information was misused. The company offered affected persons identity‑theft protection through IDX, including credit and CyberScan monitoring, a one‑million‑dollar insurance reimbursement and recovery services. It advised monitoring accounts, placing fraud alerts or security freezes, and noted the right to obtain a police report under Massachusetts law. A threat‑actor group claimed responsibility on a dark‑web forum. Separately, a subsidiary breach earlier exposed about 3.4 million individuals’ data, possibly including protected health information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Around April 21, 2026, Cognizant Technology Solutions experienced a data security breach that the company later disclosed to affected individuals. According to ClaimDepot, a threat actor group known as CoinbaseCartel claimed responsibility for the incident by posting on a dark web site hosted on the Tor network on April 15, 2026, stating that it had obtained data belonging to the organisation. Cognizant’s notification letter did not specify the number of people affected or the nature and volume of personal information involved, and the company said it had no reason to believe that the compromised information had been misused. The notice expressed regret over the incident but offered no further technical details about how the breach occurred or whether it resulted from an external cyberattack or unauthorised access. Earlier in 2026, Cognizant’s subsidiary TriZetto Provider Solutions (TPS) reported a separate data breach that exposed sensitive information of approximately 3.4 million individuals, with a filing to the Office of the Maine Attorney General indicating that the incident may have included protected health information.

In response to the breach, Cognizant offered affected individuals identity theft protection services through IDX for a period of 24 months, which included credit and CyberScan monitoring, a $1 million insurance reimbursement policy and fully managed identity theft recovery services. The company advised recipients to monitor their account statements and credit reports regularly and to remain alert for any signs of suspicious activity. It also outlined specific steps that individuals could take, such as placing fraud alerts or security freezes on their credit files with the major credit reporting agencies. Cognizant noted that, under United States federal law, consumers cannot be charged to place, lift or remove a security freeze on their credit. Additionally, the notice informed affected individuals of their right to obtain a police report relating to the incident under Massachusetts law and to file a police report if they later become victims of identity theft.
Cognizant’s notice did not disclose the method by which the breach was carried out, nor did it specify whether the incident involved an external cyberattack or unauthorised internal access, and it did not identify the categories of personal information that may have been exposed. The company did not provide further details in response to media inquiries, as an email sent to Cognizant remained unanswered by the time of publication. While the notification described the remedial measures being offered, it left open questions about the scope of the data compromised and the potential long‑term consequences for the individuals whose information was involved.