Bank of Baroda Data Leak: 1TB Sensitive Customer & Internal Audit Records Allegedly Surfaced Online; Bank Issues Security Statement

Bank of Baroda data leak

India’s second-largest public sector lender, Bank of Baroda, has found itself at the center of a major cybersecurity incident after reports surfaced that approximately 1TB of sensitive bank data – including customer identity records, loan application details, and internal audit files – was allegedly uploaded to dark web platforms.

The incident, which was first flagged by dark web monitoring platforms over the weekend of July 25–26, 2026, prompted widespread concern among millions of account holders regarding the safety of their deposits and personal information.

Following intense public scrutiny, Bank of Baroda officially released an administrative statement clarifying the scope of the breach. According to the bank, the leak stemmed from a compromised employee email account, and immediate containment protocols were activated. Crucially, the bank reassured stakeholders that its core banking systems remained uncompromised and fully secure.

What Was Leaked? Breakdown of the 1TB Data Cache

The leak came to light after cybersecurity researchers and dark web tracking platform ransomware.live detected an active download link hosted on a Tor-based dark web site. Software engineer and founder of CashlessConsumer, Srikanth Lakshmanan, shared verified screenshots of the root folder structure online, calling the leak a significant security incident.

Preliminary verification of the uploaded sample files indicates that the dataset contains a combination of sensitive customer personal identifiable information (PII) and highly confidential internal bank documentation:

1. Customer Personal & Financial Data

  • Identity Records: Customer names, Aadhaar numbers, PAN card references, and contact details across multiple branches nationwide.
  • Account Information: Savings and current account statements, NetBanking user identifiers, and customer support interaction logs.
  • Loan & Credit Files: Comprehensive loan appraisal documents, mortgage application forms, and non-resident Indian (NRI) or corporate banking service records.

2. Internal Bank Audit & Vigilance Files

  • Branch Audits: Detailed internal risk assessment reports from various regional Bank of Baroda branches.
  • Vigilance Investigations: Sensitive internal communication notes and vigilance inquiry logs.
  • bobWorld Audit Reports: Internal technical and operational evaluation documents related to the bank’s mobile application ecosystem.

Bank of Baroda Issues Official Statement: Core Systems Remain Safe

In response to growing media reports, Bank of Baroda issued a formal clarification addressing the incident:

Official Spokesperson, Bank of Baroda

The bank confirmed that a comprehensive forensic investigation has been initiated to determine the precise volume of affected records and ensure full compliance with guidelines from the Reserve Bank of India (RBI) and the Indian Computer Emergency Response Team (CERT-In).

Who is Behind the Attack? Suspected Hacker Group ‘TripleX’

While no cybercrime group has formally issued a ransom demand in public, cybersecurity analysts tracking the data dump suspect that a emerging threat actor known as TripleX may be responsible.

The threat group previously gained international attention in May 2026 after claiming responsibility for a massive 2TB data breach targeting PT Bank Negara Indonesia, one of Indonesia’s largest state-owned lenders. In both cases, the attackers made the entire dataset freely accessible on dark web forums rather than locking files behind traditional ransomware paywalls.

Is Your Money Safe? Hacking vs. Phishing Risk

For everyday Bank of Baroda customers, the immediate question is simple: Is my money still safe in my bank account?

Cybersecurity experts emphasize that a data breach is fundamentally different from a banking system breach. Because Bank of Baroda’s core banking infrastructure – which controls ledger balances, fund transfers, and vault databases – was not breached, hackers cannot directly withdraw funds or alter account balances using the leaked information alone. Furthermore, customer deposits in Indian banks remain insured up to ₹5 lakh under the Deposit Insurance and Credit Guarantee Corporation (DICGC).

However, cybersecurity professionals warn that the real danger following a data leak is not direct hacking, but social engineering and targeted phishing scams.

Cybersecurity Risk Analyst

Essential Safety Checklist for Bank of Baroda Customers

If you hold a savings account, loan, or NetBanking facility with Bank of Baroda, cybersecurity specialists recommend taking the following proactive steps immediately:

  1. Beware of Fake Customer Support Calls: Never share an OTP (One-Time Password), UPI PIN, debit card PIN, or NetBanking password over the phone. Bank officials will never call you asking for authentication codes to “block” or “verify” a leaked account.
  2. Update NetBanking & Mobile Banking Passwords: Change your password for bobWorld and online banking portals immediately using strong, unique character combinations.
  3. Enable Two-Factor Authentication (2FA): Ensure 2FA is active across all banking credentials and linked email accounts.
  4. Monitor Account Activity: Regularly review your transaction history and SMS alerts for any unrecognized debit attempts, no matter how small.
  5. Report Suspicious Activity: If you receive a suspicious call or message claiming to be from Bank of Baroda, report it immediately to the national cybercrime helpline at 1930 or via cybercrime.gov.in

Regulatory Outlook and Cyber Hygiene

The Bank of Baroda data leak highlights the ongoing challenges financial institutions face in securing distributed digital endpoints and employee email channels against sophisticated phishing attacks. As forensic auditors and regulatory authorities work to complete their assessment, Bank of Baroda customers should remain vigilant, exercise caution with incoming communications, and strictly practice safe cyber hygiene.