Representative image. Photo: Photo by Raghavan2010, Wikimedia Commons, CC BY-SA 4.0
Bank of Baroda launches probe into alleged dark web data leak
Bank of Baroda has launched a probe into an alleged data leak of nearly 1TB of data found on the dark web.
Bank of Baroda has launched a probe into an alleged data leak after nearly a terabyte of data surfaced on the dark web.
Cybersecurity researcher Srikanth Lakshmanan, founder of the consumer advocacy platform Cashless Consumer, was the first to identify the dataset listed on a dark web site over the weekend.
The alleged leak reportedly includes customer identity documents, loan application and appraisal records, internal audit reports, branch documents, customer application forms and internal communications.
Unverified reports have also claimed the dataset includes Aadhaar numbers and account details covering savings, current and loan accounts, along with NRI and corporate banking customer records.
Some researchers have connected the leak to a threat actor known as TripleX, previously linked to attacks on Indonesian financial institutions, though this remains unconfirmed.
Bank of Baroda said the incident was traced to the compromise of an employee’s email account and not any breach of its core banking systems.
“The bank’s core banking systems were not accessed and continue to remain secure,” the bank said, adding that a comprehensive forensic investigation was underway.
The bank said it was coordinating with relevant authorities as the investigation into the alleged leak progresses.
Bank of Baroda shares dropped 1.50 per cent to Rs 240.35 on the NSE on July 28, with the alleged breach compounding pressure from the bank’s weaker first-quarter FY27 earnings.
The lender said it activated containment measures immediately upon detecting the breach and was complying with all applicable regulatory requirements while the investigation continued.
Bank of Baroda is one of India’s largest public sector banks, with a network spanning thousands of branches across the country as well as international operations in several countries.
Data breaches involving Indian financial institutions have drawn increasing regulatory attention in recent years, with lenders required to report significant cybersecurity incidents to sector regulators within stipulated timeframes.
(Image: Photo by Raghavan2010, Wikimedia Commons, CC BY-SA 4.0)