Bank of Baroda Data Breach: 1TB of Customer Data Leaked on Dark Web — What We Know

Bank of Baroda Data Breach: 1TB of Customer Data Leaked on Dark Web — What We Know

India’s state-owned Bank of Baroda has confirmed a cybersecurity incident after approximately 1 terabyte of sensitive customer data and internal documents appeared on the dark web. The breach, first flagged on July 25 through dark web monitoring platforms, is linked to the hacking group TripleX and reportedly exposes millions of customers’ Aadhaar records, banking details, loan information, and account application forms. The bank says its core banking systems remain secure, but a full forensic investigation is now underway. Here is everything confirmed, alleged, and still unknown about the Bank of Baroda data breach.

What Happened: Bank of Baroda Data Breach Timeline

The incident first came to light on July 24, 2026, when a listing appeared on Ransomware.live — a dark web monitoring platform that tracks ransomware and data extortion activity. The listing claimed that a threat actor had obtained approximately 1 terabyte of data from Bank of Baroda and had published it publicly on a Tor network site, making it freely downloadable rather than holding it for ransom.

On July 25, cybersecurity researcher Srikanth Lakshmanan, founder of consumer rights platform CashlessConsumer, flagged the breach publicly on X (formerly Twitter), posting the root folder structure of the alleged data dump and alerting the RBI, CERT-In, and India’s IT Ministry. He confirmed the download link was active and described the incident as “a cyber disaster.” The alert was independently verified by dark web intelligence account @DailyDarkWeb, which posted a breakdown of the alleged dataset on the same day.

By July 27, Bank of Baroda issued an official statement acknowledging the incident. The bank confirmed that an employee’s email account had been compromised, resulting in unauthorised access to certain data. It stated that immediate containment measures had been implemented and that a comprehensive forensic investigation had been initiated in coordination with relevant regulatory authorities. The bank’s stock did not move significantly on the day of the announcement, and no stock exchange disclosure was filed as of the time of writing.

What Data Was Leaked

Based on independent verification by cybersecurity researcher Srikanth Lakshmanan and analysis reported by Reuters, The Hindu, and Times of India, the leaked dataset reportedly contains:

Customer personal data: Aadhaar numbers, names, phone numbers, photographs, and identity documents submitted during account opening. According to Ransomware.live’s documentation of the TripleX listing, the dataset includes between 100,000 and 300,000 signed customer account application forms containing photographs and identity proof documents.

Banking records: Savings account information, current account records, loan account details, NetBanking user data, NRI banking records, corporate banking service records, and branch and ATM-related information.

Internal bank documents: Branch audit reports, loan appraisal documents, internal communications, vigilance investigation records, and bobWorld audit reports — bobWorld being Bank of Baroda’s mobile banking platform.

Lakshmanan told India Today Tech: “I was able to initially verify the documents and have found a range of internal documents of the bank. This includes branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country.”

Cybersecurity analyst Bhatia, quoted by BankInfoSecurity, noted that the leaked archive contained multiple versions of an internal spreadsheet, suggesting compliance and audit documents were exposed alongside customer records. It is not yet confirmed how many individual customers are affected. The bank itself has not provided a figure, and neither RBI nor CERT-In has issued a public statement as of July 27, 2026.

Who Is Behind the Bank of Baroda Breach: The TripleX Group

The breach is attributed to a relatively new cybercrime collective known as TripleX, which first appeared in May 2026. The group primarily uses a double-extortion model — stealing data first and then threatening to publish it unless a ransom is paid. In the Bank of Baroda case, the group deviated from the typical ransom demand and instead published the entire dataset publicly for free download, reportedly as punishment for what they called weak security practices and poor password hygiene at the bank.

TripleX gained international attention in May 2026 when it breached PT Bank Negara Indonesia, one of Indonesia’s largest state-owned banks. In that incident, the group exfiltrated approximately 2 terabytes of data including customer contracts, passports, and financial transaction histories before dumping them on Tor-hosted sites. The Bank of Baroda breach follows a similar pattern — a state-owned bank, a large data volume published without ransom, and the group motivated by what it characterises as institutional negligence rather than financial gain.

No independent confirmation has fully verified TripleX’s claimed responsibility for the Bank of Baroda breach. Bank of Baroda’s official statement attributed the incident to the compromise of an employee email account, which is consistent with how the group is reported to gain initial access — through phishing or credential theft targeting individual employees rather than exploiting core system vulnerabilities directly.

Bank of Baroda’s Official Response

Bank of Baroda released a formal statement on July 27, 2026, which said: “The incident involved the compromise of an employee’s email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented.”

The bank added: “The bank’s core banking systems were not accessed and continue to remain secure.” It confirmed a comprehensive forensic investigation had begun and that it was working closely with relevant authorities in line with applicable regulatory requirements.

Notably, the bank did not file a disclosure with stock exchanges, did not quantify the number of customers affected, and did not name any specific regulatory body it was cooperating with. As of July 27, the Reserve Bank of India and CERT-In had not issued independent public statements confirming or characterising the breach. India’s Digital Personal Data Protection Act, which came into effect in 2023, requires organisations to notify the Data Protection Board and affected individuals of a data breach — it remains unclear whether formal notification procedures have been initiated.

Why This Breach Matters: Context and Implications

The Bank of Baroda breach is among the largest alleged data exposures involving an Indian public sector bank and arrives at a sensitive moment for cybersecurity in the country’s financial sector. Bank of Baroda is India’s second-largest public sector bank by assets, with over 150 million customers and branches across 17 countries.

The fact that the entry point was a single employee’s email account — rather than a sophisticated attack on Bank of Baroda’s core infrastructure — reflects a vulnerability pattern that cybersecurity experts have repeatedly flagged in India’s banking sector. State-run banks have faced consistent criticism for inadequate cybersecurity hygiene, employee training, and email security protocols compared to their private sector counterparts.

The exposure of Aadhaar data is particularly significant. Aadhaar numbers linked to financial records and identity documents create a comprehensive profile that can be used for identity theft, SIM card fraud, and fraudulent loan applications. Unlike a leaked password, an Aadhaar number cannot be changed. Affected customers face a long-term risk that persists regardless of any immediate remediation the bank undertakes.

This breach also follows a pattern of attacks on state-owned financial institutions in the region. In February 2026, around 5,000 customers of YES Bank’s multi-currency prepaid forex card were hit by fraudulent transactions worth $280,000 in a single incident. In September 2025, cybersecurity firm UpGuard reported that an exposed cloud database contained over 273,000 Indian banking records, around 6,000 of which were linked to Bank of Baroda — though that database was managed by a third party. The current breach appears unrelated to the 2025 cloud database exposure.

What Bank of Baroda Customers Should Do Right Now

If you are a Bank of Baroda account holder, taking the following steps immediately reduces your exposure while the forensic investigation continues.

Change your NetBanking password and mPIN immediately. Even though the bank says its core banking systems were not accessed, NetBanking user data is listed among the alleged leaked records. Resetting credentials is a basic protective measure regardless of whether your specific account was in the exposed dataset.

Enable two-factor authentication on bobWorld and NetBanking. If you have not already activated 2FA, do so through the bank’s app or by visiting a branch. Two-factor authentication prevents unauthorised access even when login credentials are compromised.

Monitor your bank account and linked phone number for unusual activity. Aadhaar-linked phone numbers in the leaked data could be used for SIM swap attacks — where fraudsters transfer your mobile number to a SIM they control, intercepting OTPs and gaining access to financial accounts. Contact your mobile operator to place a port lock on your number if you want additional protection.

Watch for phishing attempts. Attackers who acquire customer contact information often follow up with targeted phishing calls or messages impersonating the bank. Bank of Baroda will not ask you for your full account number, password, or OTP over phone or email. Do not respond to unsolicited contact claiming to be from the bank in the coming weeks.

Check your CIBIL or credit bureau report. If your loan application data was in the leaked set, monitoring your credit report for fraudulent loan applications in your name is prudent. Free credit report access is available through CIBIL, Experian, and Equifax India.

Regulatory and Legal Questions the Breach Raises

The Bank of Baroda data breach puts India’s Digital Personal Data Protection Act squarely in focus. The DPDPA, passed in 2023 and progressively implemented since, requires data fiduciaries — organisations that collect and process personal data — to notify the Data Protection Board of India and, in some circumstances, affected individuals when a breach occurs. The Act carries penalties for non-compliance, though the exact enforcement posture is still being established as the regulatory framework matures.

The breach also raises questions about compliance timelines and disclosure obligations. Bank of Baroda did not notify stock exchanges of the breach, which would typically be required if the incident were deemed material under SEBI’s listing obligations. Whether the bank classified this incident as material — given its stated position that core banking systems were not accessed — will likely face regulatory scrutiny.

BankInfoSecurity noted that the incident tests Bank of Baroda’s disclosure readiness and broader questions about how Indian financial institutions handle the public reporting of cybersecurity events. The contrast between TripleX’s July 24 dark web publication, Srikanth Lakshmanan’s public alert on July 25, and the bank’s official statement on July 27 represents a 72-hour gap between the breach becoming publicly known and the institution acknowledging it.

Frequently Asked Questions

Was Bank of Baroda hacked?

Bank of Baroda has confirmed a cybersecurity incident involving the compromise of an employee’s email account, which resulted in unauthorised access to certain data. The bank says its core banking systems were not accessed. Whether the full 1TB dataset claimed by the TripleX hacking group is authentic and what exactly it contains is still under forensic investigation as of July 27, 2026.

What data was leaked in the Bank of Baroda breach?

According to cybersecurity researchers who reviewed sample files, the leaked dataset includes Aadhaar numbers, names, phone numbers, photographs, account application forms, savings and current account information, loan details, NetBanking user records, NRI and corporate banking records, branch audit reports, internal communications, and vigilance investigation documents. The data allegedly spans multiple branches across India and reportedly contains between 100,000 and 300,000 customer account forms.

Who is TripleX, the group behind the Bank of Baroda breach?

TripleX is a relatively new cybercrime group that emerged in May 2026. It primarily targets financial institutions using a double-extortion model — stealing data and threatening to release it publicly unless paid. In the Bank of Baroda case, the group published the data for free, reportedly to highlight what it called weak security practices. The group previously breached PT Bank Negara Indonesia in May 2026, publishing approximately 2TB of data. No government or independent body has officially attributed the Bank of Baroda breach to TripleX; cybersecurity researchers have identified the group based on the dark web listing’s characteristics and pattern matching with prior attacks.

Are Bank of Baroda’s core banking systems safe?

Bank of Baroda has stated that its core banking systems were not accessed and remain secure. The entry point was reportedly an employee’s email account, not the bank’s central systems. However, the forensic investigation is ongoing, and the bank’s characterisation of the breach’s scope will need to be validated by independent investigators and regulators before it can be fully accepted.

What should Bank of Baroda customers do after the data breach?

Customers should immediately change their NetBanking password and bobWorld mPIN, enable two-factor authentication, monitor their accounts for unusual activity, watch for phishing attempts impersonating the bank, and check their credit bureau reports for fraudulent loan applications. If your registered mobile number may have been exposed, contact your mobile operator about placing a port lock on your number to prevent SIM swap fraud.

Has the RBI or CERT-In responded to the Bank of Baroda breach?

As of July 27, 2026, neither the Reserve Bank of India nor CERT-In had issued a public statement confirming or responding to the breach. The IT Ministry was alerted by cybersecurity researcher Srikanth Lakshmanan on July 25. Regulatory responses, if any, had not been made public at the time of writing. This article will be updated as official responses emerge.