About 1TB of Bank of Baroda’s customer data leaked on dark web

Mumbai-based bank confirmed that a forensic investigation had been launched

Must Read

- Advertisement -
- Advertisement -
  • Breach originated from a compromised employee email account, which allowed “unauthorised access to certain data.
  • Bank emphasised that its core banking systems were not accessed and “continue to remain secure”.
  • Compromised data include customer names, Aadhaar numbers, loan records, identification documents, and internal audit files, as well as corporate banking information spanning multiple branches across India.

Bank of Baroda, one of India’s largest public sector lenders, is confronting a significant cybersecurity incident after customer data and internal documents surfaced on the dark web over the weekend.

The breach, which came to light on Saturday night, has been linked to a hacking group calling itself “Triple X,” which claimed responsibility for leaking close to one terabyte of sensitive banking information.

The compromised data is reported to include customer names, Aadhaar numbers, loan records, identification documents, and internal audit files, as well as corporate banking information spanning multiple branches across India.

Cybersecurity researcher Srikanth L, founder of Cashless Consumer, who analysed the dark web listing, described the cache as containing more than 92,000 files and over 700GB of information based on metadata analysis.

The full scope of affected customers, however, remains unclear at this stage.

Raises serious questions

In a statement issued on Monday, the Mumbai-based bank confirmed that a forensic investigation had been launched and that initial containment measures were already in place. The breach, according to the bank, originated from a compromised employee email account, which allowed “unauthorised access to certain data.” Crucially, the bank emphasised that its core banking systems were not accessed and “continue to remain secure”.

Despite the bank’s assurances, the incident raises serious questions about enterprise-level email security and the vulnerability of large financial institutions that hold vast repositories of personal and corporate data.

A compromised email account, while seemingly a narrow entry point, can serve as a gateway to troves of sensitive information if proper access controls and internal segmentation are not rigorously enforced.

The leak has drawn attention from regulators and the cybersecurity community alike. The Reserve Bank of India and India’s Computer Emergency Response Team (CERT-In) has yet to issue formal responses as of Monday. Their forthcoming statements — or lack thereof — will likely shape the broader discourse on mandatory breach disclosure norms in the country’s banking sector.

This incident does not exist in isolation. In June, a cyberattack on Apple supplier Tata Electronics resulted in component design and specification documents linked to both Apple and Tesla being leaked on the dark web. Earlier this month, the ransomware group World Leaks posted files related to India’s largest nuclear plant.

The Bank of Baroda breach thus marks the third high-profile data exposure targeting Indian institutions in as many months, underscoring a troubling acceleration in the frequency and severity of cyberattacks across critical sectors.

For Bank of Baroda customers, the immediate concern centers on identity theft and financial fraud. With Aadhaar numbers and loan documents potentially in the hands of malicious actors, affected individuals could face phishing attempts, fraudulent loan applications, or unauthorised account access.

The bank has not yet disclosed whether it will offer credit monitoring or identity protection services to impacted customers, though such measures have become standard practice in comparable breaches globally.

As the forensic investigation unfolds, the incident is likely to serve as a catalyst for renewed scrutiny of cybersecurity protocols across India’s public sector banking network. The takeaway for the industry is clear: in an era where data is currency, perimeter defenses are only as strong as their weakest link — and that link is often a single, compromised inbox.

- Advertisement -

Latest News

Why the future of messaging depends on restoring trust?

Long-term success of messaging depends on sustained commitment rather than one-off interventions

Bahraini start-up unveils unique drinking water purification device

Device by Candela harnesses germicidal ultraviolet radiation to treat water directly within storage tanks

Organisations need to boost security architectures to embrace agentic AI

As organisations deploy more AI agents, they need to treat them as dynamic, continuously verified identities rather than trusted applications.
- Advertisement -
- Advertisement -

More Articles

- Advertisement -