My understanding of what happened here is that an external service (such as this one[0]), picked up the "tclzip.tatacapital.com" domain name, and through that the Google crawler also found it. At the time it found it, the "tclzip.tatacapital.com" domain had no folder restrictions, so Google's crawler was able to travel through all the directories and see the files that were in them. This appears to have been happening up until 12 months ago.
[0]: https://subdomainfinder.c99.nl/scans/2023-11-09/tatacapital....
But you can ask the moderators hn@ycombinator.com
Good luck.