S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%

 

The Wiregazette
High-quality close-up of credit and debit cards, highlighting technology and security.
Cybersecurity

Bank of Baroda Data Leak Confirmed; Compromised Email Account Exposed Customer Details, Core Systems Secure

4 分钟阅读

分享

Customer data and internal documents from India's state-run Bank of Baroda have been leaked on the dark web, the bank confirmed, after a compromised employee email account led to unauthorised access. The bank said its core banking systems remain uncompromised.

MUMBAI (The Wiregazette) — Customer data from India's state-run Bank of Baroda, along with internal documents, has been leaked on the dark web, the bank confirmed on Monday, following a compromise of an employee email account.

The Mumbai-based lender said in a statement that it had initiated a forensic investigation and was working with relevant authorities after initial containment measures. The breach involved a compromised employee email account, resulting in "unauthorised access to certain data," the bank said. "The bank's core banking systems were not accessed and continue to remain secure," it added.

The leaked data includes customer details, identification documents, loan papers and internal audit records, according to cybersecurity researcher Srikanth L, founder of Cashless Consumer. A source familiar with the matter confirmed the leak and said the bank was conducting a forensic audit. Preliminary indications suggest the incident stemmed from a compromised email system, the source said.

The data appeared on a dark web site on Saturday night and was advertised as a cache containing more than 700 gigabytes of information, based on metadata analysis of the site, Srikanth said. A separate report by livemint.com said the leak was advertised as around 1TB of data. It was not immediately clear how many customers were affected.

Bank of Baroda has not notified stock exchanges of any breach. The Reserve Bank of India and India's cybersecurity regulator CERT-In did not immediately respond to requests for comment.

**TripleX Suspected Behind Attack**

Although no hacking group has publicly claimed responsibility, livemint.com reported that Srikanth believes a relatively new cybercrime group known as TripleX may be responsible. "The attacker - TripleX - who was previously involved in an Indonesian bank - has made the entire dataset publicly available on a tor site," he told livemint.com. In May, TripleX allegedly breached PT Bank Negara Indonesia, one of Indonesia's largest state-owned banks, stealing around 2TB of data, according to the report.

The Bank of Baroda leak adds to a growing list of cybersecurity breaches affecting major Indian companies and critical institutions. In June, a cyberattack on Apple supplier Tata Electronics led to confidential component design and specification documents linked to Apple and Tesla being leaked on the dark web, according to Reuters and other sources. Earlier this month, ransomware group World Leaks posted files on the dark web related to India's largest nuclear plant, multiple sources reported.

**Customer Guidance: Phishing Risk Elevated**

Cybersecurity experts said the direct risk to customer funds is limited, but the leak significantly increases the danger of targeted phishing scams. Sudiptaa Paul Choudhury, chief marketing officer at QNu Labs, told India Today that the incident is a data breach, not a banking-systems breach. "Nobody is reporting unauthorised fund transfers, and your deposits carry DICGC insurance up to Rs 5 lakh per bank," she said.

However, she warned that personal information gives fraudsters a convincing script. "A data leak doesn't drain your account by itself, it hands scammers a script, and someone who already knows your name, your loan amount and your Aadhaar number sounds a lot more convincing when they call pretending to be your relationship manager," she said. "The leak is the loaded gun, phishing is the trigger, don't pull it for them."

Choudhury advised customers to change internet banking and mobile banking passwords immediately, enable transaction alerts, and avoid clicking any links in SMS or emails claiming to be from the bank. She also recommended locking Aadhaar biometrics through the UIDAI website or mAadhaar app, and checking credit reports for any unauthorised loan or card applications opened using leaked personal information.

The researcher Srikanth L described the scale of the incident to India Today as "a cyber disaster." The bank has not yet confirmed whether the leaked data is genuine, but said it has launched a forensic audit to determine the scope and impact.

分享

关于 Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

相关文章