A Working-Class Bank’s Data, A Ransomware Group’s “Lesson”, and 1TB of Aadhaar, PAN and Loan Files on the Dark Web
On 24 July 2026, a ransomware and extortion group calling itself “TripleX” listed Bank of Baroda one of India’s largest public sector banks on its dark web leak site. The claim: nearly 1TB (1,000GB) of internal and customer banking data, posted for free download rather than held for ransom. Within 48 hours, cybersecurity researchers had sample files circulating on social media, the bank had issued a statement, and lakhs of customers were left asking one question is my data in that file?

This blog breaks down what has actually been confirmed, what remains an unverified claim, why the bank’s own explanation matters more than the headlines, and what you should do right now if you hold a Bank of Baroda account.
What Happened: A Timeline
- July 24, 2026 — TripleX lists Bank of Baroda on Ransomware.live, a dark web monitoring platform, claiming to have exfiltrated close to 1,000GB of data.
- July 25, 2026 — Cybersecurity researcher and CashlessConsumer founder Srikanth Lakshmanan reviews sample files shared by the group and flags the incident publicly, tagging RBI and India’s Cyber Dost handle.
- July 26, 2026 — Screenshots of the alleged “root folder” of the data dump circulate widely on X (formerly Twitter). Neither RBI nor CERT-In comments.
- July 27, 2026 — Bank of Baroda breaks its silence, confirming that an employee’s email account was compromised and unauthorised access to certain internal files occurred, while maintaining that core banking infrastructure was never touched.
What Data Is Allegedly Exposed
According to the leak listing and researchers who reviewed sample files, the dataset spans both customer records and internal bank documents which is precisely what makes this incident more dangerous than a typical customer database leak.
Customer-facing data
- Aadhaar numbers and scanned Aadhaar copies
- PAN details and passport-size photographs
- Savings and current account information
- Loan applications and appraisal documents
- NetBanking user details
- NRI and corporate banking service records
Internal bank data
- Branch audit reports, including RBI audit-readiness files
- Vigilance investigation records
- Internal communications and BobWorld (the bank’s mobile app) audit reports
- Customer support material and branch/ATM-related records
Note: These are claims made by the threat actor and reviewed informally by independent researchers. Bank of Baroda has not confirmed the exact scope or volume of data affected, and a formal forensic investigation is ongoing.

At a Glance
|
Detail |
What’s Known So Far |
|
Threat actor |
Ransomware/extortion group “TripleX” |
|
Claimed volume |
Approximately 1TB (1,000GB) of data |
|
First listed |
July 24, 2026, on the leak-tracking site Ransomware.live |
|
Entry point (per BoB) |
A single compromised employee email account |
|
Core banking systems |
Bank says these were not accessed and remain secure |
|
Alleged contents |
Aadhaar copies, PAN, photographs, address/ID proof, loan files, NetBanking details, audit reports, internal communications |
|
Official confirmation |
RBI and CERT-In have not issued public confirmation; bank has acknowledged unauthorised access and launched a forensic probe |
How Did This Happen? The Bank’s Own Explanation
In its official statement, Bank of Baroda said the incident originated from a compromised employee email account not a breach of its core banking systems. TripleX itself has claimed the intrusion was possible because of weak passwords and poor security hygiene on the bank’s end, and stated the data was published for free “to teach a lesson” rather than for financial extortion.
This detail matters. A single compromised mailbox becoming a pipeline for a terabyte of sensitive files, including audit-readiness documents and vigilance records, points to a much larger failure: inadequate access segmentation. In a well-architected environment, an individual employee’s email credentials should never be a doorway to bulk customer KYC data or internal audit repositories. When one compromised identity can reach that much, the perimeter was never the real control the access design was.

Who Is TripleX?
TripleX is a ransomware and data-extortion group that has been active through 2026. Notably, this is not its first move against a financial institution the group previously claimed responsibility for a breach at Bank Negara Indonesia in June 2026, where it leaked customer contracts and passport data. The Bank of Baroda incident fits the same pattern: identify a soft entry point, exfiltrate broadly, and publish rather than negotiate, maximising reputational damage over financial payout.
Why This Isn’t Just Bank of Baroda’s Problem
This incident lands in a familiar pattern for Indian financial and telecom institutions. Juspay, Airtel, and multiple other large Indian enterprises have faced similar allegations in recent years, and the underlying story rarely changes: a single point of compromise, delayed public disclosure, and an aftermath where customers find out from social media before they hear from the institution holding their data.
India’s regulatory stack is not silent on this. CERT-In mandates that regulated entities report cybersecurity incidents within six hours of detection, and the DPDP Act imposes data-fiduciary obligations, including breach notification, on entities handling personal data. Whether this incident is reported and handled within that framework is now a matter regulators, not just customers, need to track.
What Bank of Baroda Customers Should Do Right Now
- Do not install any APK file sent to you over WhatsApp or SMS, even if the sender appears to know your PAN, Aadhaar, or loan details.
- Never share an OTP with anyone, including callers who sound convincingly official or already seem to know your account information.
- Treat any unsolicited call about “KYC re-verification” or “urgent account update” with suspicion, and verify independently by calling the bank’s official helpline.
- Monitor your bank statements and credit report for unfamiliar transactions or loan enquiries over the coming weeks.
- Consider freezing or closely monitoring your Aadhaar-based authentication (via UIDAI’s mAadhaar app) if you suspect exposure.
- Report suspicious calls or messages to the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline.
The Bigger Lesson for Indian Enterprises
Whatever the forensic investigation ultimately confirms about scope, one structural lesson is already visible: identity and access management, not just perimeter defence, is where large Indian institutions keep getting caught out. A compromised inbox should never be able to reach five versions of an RBI audit-readiness file. Least-privilege access, continuous monitoring of what an identity can reach, and rapid, transparent incident communication are no longer optional line items they are the difference between a contained incident and a terabyte on the dark web.
Silence is also a cost. In this case, the bank’s own customers learned about a possible breach from independent researchers on social media, hours before any official acknowledgement. In a threat landscape where fraud calls follow leaks within days, the gap between detection and disclosure is exactly the window fraudsters use.
How Threatsys Helps Secure Banks Against Modern Cyber Threats
![]()
As cyber threats targeting banks continue to evolve, financial institutions need more than reactive security they require continuous security assessments, rapid incident response, and regulatory compliance to stay protected. Threatsys helps banks, NBFCs, fintech companies, and financial service providers strengthen their cybersecurity posture through comprehensive security testing, cyber forensics, and compliance-driven security services.
Our Banking-Focused Cybersecurity Services Include:
Cyber Forensics & Incident Response
Cyberattacks can disrupt banking operations and expose sensitive financial data within minutes. Threatsys provides comprehensive cyber forensics and incident response services to help financial institutions quickly investigate security incidents, minimize damage, and restore normal operations while preserving critical digital evidence.
-
Investigate cybersecurity incidents and data breaches.
-
Preserve digital evidence for legal and regulatory requirements.
-
Identify attack vectors and perform root cause analysis.
-
Support recovery and remediation following cyberattacks.
Application Security Testing
Banking applications are among the most targeted digital assets due to the sensitive financial information they process. Threatsys performs in-depth security testing to identify vulnerabilities across web, mobile, API, and network environments, helping organizations secure customer-facing applications before attackers can exploit them.
-
Web Application Security Testing to identify vulnerabilities in internet banking portals.
-
Mobile Application Security Testing to secure Android and iOS banking applications.
-
API Security Testing to protect banking APIs and third-party integrations.
-
Network Penetration Testing to assess internal and external banking networks.
Infrastructure & Cloud Security
Modern banking depends on secure cloud platforms, enterprise networks, and critical IT infrastructure. Threatsys helps organizations identify infrastructure weaknesses, misconfigurations, and security gaps that could expose critical banking systems to cyber threats.
-
Cloud Security Testing to secure cloud-hosted banking environments.
-
Infrastructure Security Testing to identify weaknesses in critical IT infrastructure.
-
Enterprise Security Testing to evaluate enterprise-wide security controls.
-
Thick Client Security Testing to secure desktop-based banking applications.
Advanced Threat Detection & Monitoring
Sophisticated cyberattacks often bypass traditional security controls. Threatsys strengthens an organization’s detection and response capabilities through realistic attack simulations and continuous security monitoring, enabling financial institutions to identify and contain threats before they impact business operations.
-
Red Teaming Attack Simulation to emulate real-world cyberattacks.
-
SOC as a Service (SOCaaS) for continuous monitoring, threat detection, and rapid incident response.
Dark Web Monitoring
Stolen banking credentials and sensitive customer information frequently appear on underground marketplaces before organizations become aware of a compromise. Threatsys continuously monitors the dark web to identify exposed data and emerging threats, allowing financial institutions to take proactive action.
-
Detect leaked credentials and exposed customer information.
-
Monitor underground forums for emerging cyber threats targeting financial institutions.
Compliance & Regulatory Services
Banks and financial institutions must comply with multiple cybersecurity regulations and industry standards to protect customer data and maintain operational resilience. Threatsys helps organizations achieve and maintain compliance through comprehensive security assessments, audits, and governance consulting.
-
GRC Consulting to help meet regulatory and industry security requirements.
Security Consulting & Governance
Building a mature cybersecurity program requires more than technical assessments. Threatsys provides strategic consulting, secure development practices, and governance services that help financial institutions strengthen their overall security posture and establish long-term cyber resilience.
-
Secure Source Code Review to identify security flaws during development.
-
System Hardening to strengthen servers, endpoints, and operating systems.
-
Security Consulting to improve overall cybersecurity strategy.
-
vCISO Services to enhance enterprise-wide security governance and leadership.
From proactive security assessments and penetration testing to cyber forensics, compliance management, and continuous security monitoring, Threatsys enables financial institutions to reduce cyber risk, protect sensitive customer data, and build resilient digital banking ecosystems capable of withstanding today’s evolving threat landscape.
Conclusion
The full extent of the Bank of Baroda data leak is still being established, and the bank maintains that its core systems were never compromised. But the claims already in circulation Aadhaar copies, loan files, audit reports, and internal vigilance records are serious enough that every Bank of Baroda customer, especially from potentially affected branches, should treat this as an active risk and not a rumour to wait out.
This story will keep developing as the forensic investigation, RBI’s response, and CERT-In’s involvement become clearer. What won’t change is the basic advice: stay sceptical of anyone who calls claiming to be your bank, never install unknown APKs, and never share an OTP no matter how much the caller already seems to know.
To stay ahead, businesses must adopt proactive, intelligence-driven security strategies that simulate real-world threats and continuously validate their defenses. With Threatsys , organizations can build a resilient and future-ready security framework—ensuring their systems remain protected in an increasingly connected world.

Stay secure, Stay aware with Threatsys.

