Bank of Baroda Data Leak Exposes Customer Records, Core Systems Unaffected, Bank Says
Customer data and internal documents from India’s state-run Bank of Baroda have been leaked on the dark web, the bank confirmed, attributing the breach to a compromised employee email account. The lender said its core banking systems were not accessed.
MUMBAI, July 27 (The Wiregazette) – Customer data from Bank of Baroda, including identification documents, loan papers and internal audit records, has been leaked on the dark web, according to a source familiar with the matter and a cybersecurity researcher. The Mumbai-based state-run lender said in a statement Monday that it had launched a forensic investigation and implemented initial containment measures after a compromised employee email account led to “unauthorised access to certain data.”
“The bank’s core banking systems were not accessed and continue to remain secure,” the statement added, according to multiple reports.
The data surfaced on a dark web site on Saturday night and was advertised as a cache containing more than 700 gigabytes of information, based on a metadata analysis of the site, said cybersecurity researcher Srikanth L, founder of Cashless Consumer. Some reports, citing the threat actor’s claim, put the size at around 1 terabyte, though that figure has not been independently verified by the bank.
Srikanth L told India Today that the breach first came to light on Saturday, July 25, after being flagged by the dark web monitoring platform ransomeware.live. He said his preliminary verification indicated the files contained both internal bank records and customer information, including application forms across multiple branches, branch audits, loan appraisal documents, internal communications and vigilance investigations.
“I was able to initially verify the documents and have found a range of internal documents of the bank,” he told India Today Tech.
The leaked data includes customer details, identity documents such as Aadhaar numbers, loan papers and internal audit records, Srikanth L said. The researcher also shared screenshots on X, saying the download link was active.
Bank of Baroda has not notified stock exchanges of the incident, according to Business Standard. The Reserve Bank of India and India’s cybersecurity regulator CERT-In did not immediately respond to requests for comment, several outlets reported.
**Suspected attacker and industry context**
While no hacking group has publicly claimed responsibility, Srikanth L believes the relatively new cybercrime group TripleX may be responsible, according to livemint.com. TripleX was previously involved in a breach of Indonesia’s PT Bank Negara Indonesia in May, where the group reportedly stole around 2TB of data, livemint.com reported.
The leak comes amid growing concerns over cybersecurity risks facing large companies and financial institutions that store vast amounts of customer data. In June, a cyberattack on Apple supplier Tata Electronics led to component design documents linked to Apple and Tesla being leaked on the dark web, as reported by Reuters and other sources. Earlier this month, ransomware group World Leaks posted files on the dark web related to India’s largest nuclear plant.
**Bank response and customer risk**
Bank of Baroda said it has robust information security protocols in place. “The incident involved the compromise of an employee’s email. The matter was identified promptly, necessary action has been initiated, the core banking system remains uncompromised, and a forensic review has been launched,” the bank said, according to NDTV Profit.
It remains unclear how many customers may be affected. A source familiar with the matter told Reuters and Business Standard that preliminary indications suggest the breach originated from a compromised email system rather than the bank’s core infrastructure.
Cybersecurity experts said the immediate risk to customers is not direct unauthorised fund transfers, but sophisticated phishing attacks. “A data leak doesn’t drain your account by itself, it hands scammers a script,” Sudiptaa Paul Choudhury, CMO at QNu Labs, told India Today. “Someone who already knows your name, your loan amount and your Aadhaar number sounds a lot more convincing when they call pretending to be your relationship manager. That’s the moment money actually moves, because you let it.”
The expert advised customers to change internet banking and mobile banking passwords, enable transaction alerts, and avoid clicking links in unsolicited messages. “Don’t wait for confirmation, act like it’s real,” Choudhury said, urging customers to lock Aadhaar biometrics through the UIDAI website and check credit reports for any unauthorised accounts.
The Wiregazette reported earlier that the banking sector has been under increased scrutiny from regulators and investors over data protection practices. The latest incident at Bank of Baroda, one of India’s largest public sector lenders, is likely to heighten those concerns.
相关文章
您可能还喜欢




