The Bank of Baroda data leak has sent shockwaves across India’s financial sector following allegations that a threat actor has exposed approximately one terabyte (1TB) of sensitive internal and customer records.The data, which reportedly covers a wide range of corporate and individual banking services, has been made available on dark web platforms without any monetary paywall.
While official cybersecurity monitoring agencies and regulators have yet to verify the claims, initial independent investigations by security researchers suggest that the compromised repository contains deep operational documents alongside personal banking data.
What Information Was Reportedly Exposed?
The scale of the alleged breach is substantial, spanning individual retail accounts, corporate profiles, and administrative records across multiple branches nationwide. According to samples reviewed by cybersecurity analysts, the dataset touches nearly every layer of the bank’s digital footprint.
The allegedly exposed contents include:
Customer Banking Records:Savings and current account details, loan application documents, customer support interaction logs, and NetBanking user information. Whether it is the Aadhaar number, the name, or loans taken from various branches across India.
Identification Documents:Application forms containing personal identifiers, names, addresses, and government identification numbers.
Internal Operational Files:Branch audit reports, internal communications, vigilance investigation files, and audit logs related to the bank’s mobile application, bobWorld.
Corporate & NRI Data:Loan appraisal records, corporate transaction data, and Non-Resident Indian (NRI) account servicing documentation.
How Was the Breach Discovered?
The incident came to light after threat intelligence platforms flagged the public distribution of the files.Dark web tracking service ransomware.live first picked up traces of the leak on Saturday, July 25.
Following the alert, Srikanth Lakshmanan—a software engineer and founder of the open-data research initiative CashlessConsumer—analyzed publicly accessible sample files released by the attacker.Lakshmanan confirmed that the links were active and contained verified internal documentation spanning multiple branches across India, calling the development a severe cyber incident.
“I was able to initially verify the documents and have found a range of internal documents of the bank… including branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country.”
— Srikanth Lakshmanan, Founder of CashlessConsumer
Srikanth Lakshmanan posted screenshots of the sample documents on X
Who is Responsible for the Attack?
While no official confirmation has been made, security researchers point toward a relatively new cybercriminal group operating under the alias TripleX.
[Alleged Attack Timeline]
|
+------------------------+------------------------+
| |
May 2026: PT Bank Negara BNI July 2026: Bank of Baroda
(Indonesia's State Bank) (Indian Public Sector Bank)
• 2TB Data Stolen • 1TB Data Allegedly Dumped
• Contracts, Transactions & IDs • Audits, Customer Files & Loans
TripleX previously gained attention in May after targeting PT Bank Negara Indonesia (BNI), one of Indonesia’s largest state-owned banks. During that incident, the group exfiltrated roughly 2TB of data, which included financial transaction histories, operational contracts, and internal records. The pattern observed in the Bank of Baroda incident closely matches the tactics and distribution methods used in the Indonesian breach, with the actor releasing the full dataset directly onto a Tor-based network.
Official Response and Current Status
At present, Bank of Baroda has not issued a formal public statement regarding the integrity of its infrastructure or the status of customer data.Neither the Reserve Bank of India (RBI) nor the Indian Computer Emergency Response Team (CERT-In) has publicly acknowledged or verified the incident.
This development arrives during a period of heightened scrutiny around critical infrastructure protection in the financial sector.Regulators globally have been urging banks to tighten third-party cloud security, audit internal systems, and prepare for increasingly sophisticated threat models.
Recommended Measures for Bank Customers
Although regulatory investigation remains pending, account holders are advised to adopt immediate defensive digital hygiene practices:
Update NetBanking Credentials: Change passwords and security PINs across mobile banking applications and NetBanking portals immediately.
Enable Multi-Factor Authentication (MFA): Ensure 2FA/MFA is enabled across all financial applications linked to primary mobile numbers.
Monitor Account Activity: Regularly audit transaction histories for unexpected withdrawals or small test debits.
Beware of Phishing: Be alert to unsolicited calls, SMS messages, or emails requesting OTPs, banking credentials, or personal verification under the guise of bank personnel or fraud prevention units.