Bank of Baroda is probing an alleged data leak after close to a terabyte of data reportedly involving customer records surfaced on the dark web.
Cybersecurity researcher Srikanth Lakshmanan, founder of the consumer advocacy platform Cashless Consumer, first identified the dataset listed on a dark web site over the weekend.
The alleged leak reportedly includes customer identity documents, loan application and appraisal records, internal audit reports, branch documents, customer application forms and internal communications.
Some unverified reports have claimed the dataset also includes Aadhaar numbers and account records tied to savings, current and loan accounts, as well as NRI and corporate banking customers.
Researchers have suggested a possible link to a threat actor known as TripleX, previously associated with attacks on Indonesian financial institutions, though this remains unconfirmed.
Bank of Baroda said the incident stemmed from the compromise of an employee’s email account rather than any breach of its core banking systems.
“The bank’s core banking systems were not accessed and continue to remain secure,” the bank said, confirming that a comprehensive forensic investigation was underway.
The bank said it continues to work with relevant authorities as the investigation into the alleged breach proceeds.
Bank of Baroda’s shares slipped 1.50 per cent to Rs 240.35 on the NSE on July 28, as the alleged breach added to concerns following the bank’s weaker first-quarter FY27 earnings.
The bank said it had put containment measures in place immediately upon detecting the breach and was complying with all applicable regulatory requirements during the ongoing investigation.
Bank of Baroda is one of India’s largest public sector banks, with a network spanning thousands of branches across the country as well as international operations in several countries.
Data breaches involving Indian financial institutions have drawn increasing regulatory attention in recent years, with lenders required to report significant cybersecurity incidents to sector regulators within stipulated timeframes.
(Image: Photo by Raghavan2010, Wikimedia Commons, CC BY-SA 4.0)