New Delhi: State-owned Bank of Baroda (BoB) is investigating a major cybersecurity incident after a threat actor allegedly leaked a massive cache of customer and internal banking data on the dark web. Initial reports claimed the exposed dataset was around 1TB in size and contained sensitive customer information, including Aadhaar details, account records, loan documents and internal audit files.

In response to the reports, Bank of Baroda confirmed that the incident involved the compromise of an employee’s email account, resulting in unauthorised access to certain data. The bank said its core banking systems were not accessed and remain secure, and that a forensic investigation is underway in coordination with relevant authorities.

What data was reportedly exposed?

According to cybersecurity researcher Srikanth Lakshmanan, who first highlighted the incident, the leaked data allegedly includes:

  • Customer names and contact details.
  • Aadhaar and KYC-related documents.
  • Savings and current account information.
  • Loan applications and appraisal records.
  • Net banking user details.
  • Corporate and NRI banking records.
  • Internal audit reports and branch documents.

The researcher said sample files shared by the threat actor appeared to contain genuine internal bank documents. However, the total size and full extent of the leak have not been independently verified.

Bank issues official statement

Bank of Baroda said the breach was limited to data accessible through a compromised employee email account.

In a statement, the lender said immediate containment measures had been implemented after the incident was detected. It added that its core banking platform and customer transaction systems were unaffected, and normal banking operations continue without disruption. A comprehensive forensic investigation is being conducted while the bank works with the relevant authorities in line with regulatory requirements.

Who may be behind the attack?

The alleged breach has been linked by some cybersecurity researchers to a relatively new hacking group known as TripleX, which has previously been associated with attacks on financial institutions in Southeast Asia.

The group reportedly uploaded the data to a dark web portal, although no official agency has attributed responsibility for the attack. Authorities have not confirmed the identity of the attackers.

Authorities monitoring the incident

As of now, neither the Reserve Bank of India (RBI) nor the Indian Computer Emergency Response Team (CERT-In) has publicly commented on the breach.

The incident has renewed concerns over cybersecurity risks facing India’s banking sector, particularly as financial institutions increasingly rely on digital infrastructure to serve millions of customers.

What should customers do?

Although the bank has stated that its core banking systems remain secure, cybersecurity experts recommend that customers take precautionary steps:

  • Monitor bank accounts for any unauthorised transactions.
  • Change passwords for internet and mobile banking.
  • Enable two-factor authentication where available.
  • Be cautious of phishing emails, SMS messages and fraudulent phone calls claiming to be from the bank.
  • Report suspicious activity to the bank immediately.

Conclusion

The alleged Bank of Baroda data breach has raised fresh questions about cybersecurity in India’s banking sector. While the bank maintains that only an employee email account was compromised and that its core banking infrastructure remains secure, the ongoing forensic investigation will determine the full scope of the incident and whether customer data has been significantly affected.