Bank of Baroda Confirms Employee Email Breach as Hackers Claim to Dump 1TB of Customer Data on Dark Web
Bank of Baroda Confirms Employee Email Breach as Hackers Claim to Dump 1TB of Customer Data on Dark Web #
Bank of Baroda has confirmed a cybersecurity incident in which an employee’s email account was compromised, giving attackers unauthorised access to customer and internal data. India’s second-largest public-sector bank disclosed the breach on 27 July, saying containment measures had been put in place promptly and that its core banking systems had not been accessed.
“The incident involved compromise of an employee’s email account, resulting in unauthorised access to certain data,” the bank said in a statement. It added that a forensic investigation has been launched and that it is cooperating with relevant regulatory authorities.
The confirmation followed a dark-web listing dated 24 July, in which hacking group TripleX claimed to have published nearly one terabyte of Bank of Baroda data for free. According to Business Standard, the alleged dataset includes savings and current account information, loan account details, net banking user data, records relating to non-resident Indian customers, corporate banking material, and branch and ATM-related data. A listing on dark-web monitoring platform Ransomware.live suggested the trove could contain between 100,000 and 300,000 customer application forms, including photographs and identity documents submitted during account opening.
Independent digital-payments researcher Srikanth Lakshmanan separately examined the leaked material and said it included customer details, identification documents, loan papers, and internal audit records, according to The Asian Banker.
The bank, majority-owned by the Indian government, reported global business of INR 30.51 trillion (approximately $319 billion) as of June 2026 and operates more than 8,400 domestic branches. It has reportedly filed a preliminary notification under a cyber-insurance programme administered by National Insurance, which provides total cover of INR 7.5 billion (around $78 million). The value of any potential claim has not yet been determined.
Under India’s existing framework, the Computer Emergency Response Team (CERT-In) requires organisations to report specified cyber incidents within six hours of detection, and the Reserve Bank of India’s Cyber Security Framework for Banks sets a similar two-to-six-hour window for initial regulatory notification. Bank of Baroda has not disclosed when it became aware of the breach or when it notified authorities, a detail regulators are likely to scrutinise when assessing whether reporting obligations were met.
The investigation is ongoing. Forensic teams have not yet determined the full scale of the breach, identified all affected customers, or established whether any exposed records have been used for fraud. India’s breach-notification rules will also tighten in May 2027, when the Digital Personal Data Protection Rules take effect, requiring organisations to notify affected individuals promptly and report detailed information to the Data Protection Board within 72 hours.