New Delhi: Bank of Baroda has reportedly faced a major cybersecurity incident after a threat actor allegedly claimed to have accessed and leaked around 1TB of sensitive data on the dark web. The alleged breach reportedly includes customer and corporate banking information, including names, account-related details, Aadhaar numbers, loan records and internal banking documents.

The bank, however, has clarified that its core banking systems were not compromised. In a statement shared on social media platform X, Bank of Baroda said the incident involved the compromise of an employee’s email account, which resulted in unauthorised access to certain data. The bank added that immediate containment measures were implemented and a detailed forensic investigation was underway.

Bank denies core banking system compromise

According to Bank of Baroda’s statement, the incident did not involve direct access to its core banking infrastructure. The bank said its core systems remained secure and that it was working with relevant authorities as part of the investigation.

The alleged breach reportedly involved data accessed through an employee email account. The bank has initiated internal checks to determine the extent of the exposure and verify the authenticity of the information being circulated online.

Cybersecurity experts have highlighted that even when core banking systems remain unaffected, unauthorised access to employee accounts can create significant risks if sensitive documents and customer information are exposed.

Alleged leaked data includes customer and corporate records

The threat actor allegedly made around 1TB of data available online, claiming it contained information from multiple Bank of Baroda branches across India.

The alleged leaked information reportedly includes:

  • Savings and current account records
  • Loan-related documents
  • NetBanking user information
  • NRI banking records
  • Corporate banking details
  • Customer support material
  • Branch and ATM-related records
  • Internal banking documents

Cybersecurity observers have raised concerns over the potential misuse of such information, particularly personal identification details and financial records.

Cybersecurity researcher highlights leaked documents

Software engineer and CashlessConsumer founder Srikanth Lakshmanan reportedly identified samples of the leaked data circulating online. He claimed that the shared documents appeared to include internal bank records and customer-related information.

According to reports, the leaked samples allegedly contained branch audit documents, loan appraisal records, internal communications, vigilance investigation files, bobWorld audit reports and customer application forms from multiple branches.

Srikanth described the incident as a major cybersecurity failure, stating that the documents he reviewed appeared to contain sensitive internal information.

The breach was reportedly first detected on Saturday, July 25, by dark web monitoring platform Ransomware.live, which tracks cyberattacks and leaked datasets.

Possible involvement of TripleX hacking group

No hacker group has officially claimed responsibility for the alleged Bank of Baroda breach. However, cybersecurity researcher Srikanth Lakshmanan suggested that the relatively new hacking group TripleX could be behind the incident.

The group has previously been linked to a cyberattack on Indonesia’s state-owned bank PT Bank Negara Indonesia in May 2026. In that incident, the group reportedly claimed to have stolen around 2TB of data, including contracts, personal identification information, financial transaction details and internal banking documents.

Authorities and cybersecurity experts are still investigating whether TripleX was actually responsible for the Bank of Baroda incident.

Growing cybersecurity concerns in banking sector

The alleged data leak comes amid increasing concerns over cybersecurity threats targeting financial institutions worldwide. Banks hold vast amounts of sensitive customer information, making them frequent targets for cybercriminal groups.

The use of artificial intelligence in cyberattacks has further increased concerns among security professionals. Financial institutions in India have been advised to strengthen security systems, improve employee awareness and implement stronger safeguards against data theft.

While Bank of Baroda has not confirmed the full scale of the alleged breach, the incident highlights the importance of protecting employee accounts, third-party systems and internal databases.

Previous data exposure linked to third-party systems

This is not the first time Bank of Baroda-related data has appeared in cybersecurity discussions. In September 2025, cybersecurity firm UpGuard reportedly identified an exposed cloud database containing more than 2,73,000 Indian banking records, including around 6,000 records linked to Bank of Baroda.

However, that incident was reportedly associated with a third-party system and not the bank’s internal infrastructure.

The latest alleged breach has once again raised questions about data security practices across financial organisations and the need for stronger monitoring of external platforms.

Bank continues investigation

Bank of Baroda has said it is conducting a comprehensive forensic investigation and coordinating with relevant authorities. The bank has assured that necessary steps are being taken to contain the issue and protect customer interests.

Customers are advised to remain cautious, avoid sharing banking credentials and monitor their accounts for any unusual activity. Financial institutions generally recommend using strong passwords, enabling additional security features and being alert to suspicious messages or calls.

Conclusion

The alleged Bank of Baroda data leak has raised serious cybersecurity concerns after claims of a 1TB dataset being exposed online. While the bank has clarified that its core banking systems remain secure, the incident underlines the growing threat faced by financial institutions. The ongoing investigation will determine the authenticity and extent of the leaked information, while stronger cybersecurity measures will remain crucial to protect customer data in the future.