icon
Have any questions?
Call: 09668200222
Cyber Security News & Events Penetration Testing Quick Tips

Bank of Baroda Data Leak: Inside the Alleged 1,000GB Breach Every Customer Should Know About

A Working-Class Bank’s Data, A Ransomware Group’s “Lesson”, and 1TB of Aadhaar, PAN and Loan Files on the Dark Web

On 24 July 2026, a ransomware and extortion group calling itself “TripleX” listed Bank of Baroda one of India’s largest public sector banks on its dark web leak site. The claim: nearly 1TB (1,000GB) of internal and customer banking data, posted for free download rather than held for ransom. Within 48 hours, cybersecurity researchers had sample files circulating on social media, the bank had issued a statement, and lakhs of customers were left asking one question is my data in that file?

Bank of baroda data leak

This blog breaks down what has actually been confirmed, what remains an unverified claim, why the bank’s own explanation matters more than the headlines, and what you should do right now if you hold a Bank of Baroda account.

What Happened: A Timeline

  • July 24, 2026 — TripleX lists Bank of Baroda on Ransomware.live, a dark web monitoring platform, claiming to have exfiltrated close to 1,000GB of data.
  • July 25, 2026 — Cybersecurity researcher and CashlessConsumer founder Srikanth Lakshmanan reviews sample files shared by the group and flags the incident publicly, tagging RBI and India’s Cyber Dost handle.
  • July 26, 2026 — Screenshots of the alleged “root folder” of the data dump circulate widely on X (formerly Twitter). Neither RBI nor CERT-In comments.
  • July 27, 2026 — Bank of Baroda breaks its silence, confirming that an employee’s email account was compromised and unauthorised access to certain internal files occurred, while maintaining that core banking infrastructure was never touched.

What Data Is Allegedly Exposed

According to the leak listing and researchers who reviewed sample files, the dataset spans both customer records and internal bank documents which is precisely what makes this incident more dangerous than a typical customer database leak.

Customer-facing data

  • Aadhaar numbers and scanned Aadhaar copies
  • PAN details and passport-size photographs
  • Savings and current account information
  • Loan applications and appraisal documents
  • NetBanking user details
  • NRI and corporate banking service records

Internal bank data

  • Branch audit reports, including RBI audit-readiness files
  • Vigilance investigation records
  • Internal communications and BobWorld (the bank’s mobile app) audit reports
  • Customer support material and branch/ATM-related records

Note: These are claims made by the threat actor and reviewed informally by independent researchers. Bank of Baroda has not confirmed the exact scope or volume of data affected, and a formal forensic investigation is ongoing.

Bank of baroda data leak 1

At a Glance

Detail

What’s Known So Far

Threat actor

Ransomware/extortion group “TripleX”

Claimed volume

Approximately 1TB (1,000GB) of data

First listed

July 24, 2026, on the leak-tracking site Ransomware.live

Entry point (per BoB)

A single compromised employee email account

Core banking systems

Bank says these were not accessed and remain secure

Alleged contents

Aadhaar copies, PAN, photographs, address/ID proof, loan files, NetBanking details, audit reports, internal communications

Official confirmation

RBI and CERT-In have not issued public confirmation; bank has acknowledged unauthorised access and launched a forensic probe

 

How Did This Happen? The Bank’s Own Explanation

In its official statement, Bank of Baroda said the incident originated from a compromised employee email account not a breach of its core banking systems. TripleX itself has claimed the intrusion was possible because of weak passwords and poor security hygiene on the bank’s end, and stated the data was published for free “to teach a lesson” rather than for financial extortion.

This detail matters. A single compromised mailbox becoming a pipeline for a terabyte of sensitive files, including audit-readiness documents and vigilance records, points to a much larger failure: inadequate access segmentation. In a well-architected environment, an individual employee’s email credentials should never be a doorway to bulk customer KYC data or internal audit repositories. When one compromised identity can reach that much, the perimeter was never the real control the access design was.

Bank of baroda data leak 2

Who Is TripleX?

TripleX is a ransomware and data-extortion group that has been active through 2026. Notably, this is not its first move against a financial institution the group previously claimed responsibility for a breach at Bank Negara Indonesia in June 2026, where it leaked customer contracts and passport data. The Bank of Baroda incident fits the same pattern: identify a soft entry point, exfiltrate broadly, and publish rather than negotiate, maximising reputational damage over financial payout.

Why This Isn’t Just Bank of Baroda’s Problem

This incident lands in a familiar pattern for Indian financial and telecom institutions. Juspay, Airtel, and multiple other large Indian enterprises have faced similar allegations in recent years, and the underlying story rarely changes: a single point of compromise, delayed public disclosure, and an aftermath where customers find out from social media before they hear from the institution holding their data.

India’s regulatory stack is not silent on this. CERT-In mandates that regulated entities report cybersecurity incidents within six hours of detection, and the DPDP Act imposes data-fiduciary obligations, including breach notification, on entities handling personal data. Whether this incident is reported and handled within that framework is now a matter regulators, not just customers, need to track.

What Bank of Baroda Customers Should Do Right Now

  • Do not install any APK file sent to you over WhatsApp or SMS, even if the sender appears to know your PAN, Aadhaar, or loan details.
  • Never share an OTP with anyone, including callers who sound convincingly official or already seem to know your account information.
  • Treat any unsolicited call about “KYC re-verification” or “urgent account update” with suspicion, and verify independently by calling the bank’s official helpline.
  • Monitor your bank statements and credit report for unfamiliar transactions or loan enquiries over the coming weeks.
  • Consider freezing or closely monitoring your Aadhaar-based authentication (via UIDAI’s mAadhaar app) if you suspect exposure.
  • Report suspicious calls or messages to the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline.

Bank of baroda data leak_3

The Bigger Lesson for Indian Enterprises

Whatever the forensic investigation ultimately confirms about scope, one structural lesson is already visible: identity and access management, not just perimeter defence, is where large Indian institutions keep getting caught out. A compromised inbox should never be able to reach five versions of an RBI audit-readiness file. Least-privilege access, continuous monitoring of what an identity can reach, and rapid, transparent incident communication are no longer optional line items they are the difference between a contained incident and a terabyte on the dark web.

Silence is also a cost. In this case, the bank’s own customers learned about a possible breach from independent researchers on social media, hours before any official acknowledgement. In a threat landscape where fraud calls follow leaks within days, the gap between detection and disclosure is exactly the window fraudsters use.

How Threatsys Helps Secure Banks Against Modern Cyber Threats

red teaming in 2026 India

As cyber threats targeting banks continue to evolve, financial institutions need more than reactive security they require continuous security assessments, rapid incident response, and regulatory compliance to stay protected. Threatsys helps banks, NBFCs, fintech companies, and financial service providers strengthen their cybersecurity posture through comprehensive security testing, cyber forensics, and compliance-driven security services.

Our Banking-Focused Cybersecurity Services Include:

Cyber Forensics & Incident Response

Cyberattacks can disrupt banking operations and expose sensitive financial data within minutes. Threatsys provides comprehensive cyber forensics and incident response services to help financial institutions quickly investigate security incidents, minimize damage, and restore normal operations while preserving critical digital evidence.

  • Investigate cybersecurity incidents and data breaches.

  • Preserve digital evidence for legal and regulatory requirements.

  • Identify attack vectors and perform root cause analysis.

  • Support recovery and remediation following cyberattacks.

Application Security Testing

Banking applications are among the most targeted digital assets due to the sensitive financial information they process. Threatsys performs in-depth security testing to identify vulnerabilities across web, mobile, API, and network environments, helping organizations secure customer-facing applications before attackers can exploit them.

Infrastructure & Cloud Security

Modern banking depends on secure cloud platforms, enterprise networks, and critical IT infrastructure. Threatsys helps organizations identify infrastructure weaknesses, misconfigurations, and security gaps that could expose critical banking systems to cyber threats.

Advanced Threat Detection & Monitoring

Sophisticated cyberattacks often bypass traditional security controls. Threatsys strengthens an organization’s detection and response capabilities through realistic attack simulations and continuous security monitoring, enabling financial institutions to identify and contain threats before they impact business operations.

Dark Web Monitoring

Stolen banking credentials and sensitive customer information frequently appear on underground marketplaces before organizations become aware of a compromise. Threatsys continuously monitors the dark web to identify exposed data and emerging threats, allowing financial institutions to take proactive action.

  • Detect leaked credentials and exposed customer information.

  • Monitor underground forums for emerging cyber threats targeting financial institutions.

Compliance & Regulatory Services

Banks and financial institutions must comply with multiple cybersecurity regulations and industry standards to protect customer data and maintain operational resilience. Threatsys helps organizations achieve and maintain compliance through comprehensive security assessments, audits, and governance consulting.

Security Consulting & Governance

Building a mature cybersecurity program requires more than technical assessments. Threatsys provides strategic consulting, secure development practices, and governance services that help financial institutions strengthen their overall security posture and establish long-term cyber resilience.

From proactive security assessments and penetration testing to cyber forensics, compliance management, and continuous security monitoring, Threatsys enables financial institutions to reduce cyber risk, protect sensitive customer data, and build resilient digital banking ecosystems capable of withstanding today’s evolving threat landscape.

Conclusion

The full extent of the Bank of Baroda data leak is still being established, and the bank maintains that its core systems were never compromised. But the claims already in circulation Aadhaar copies, loan files, audit reports, and internal vigilance records are serious enough that every Bank of Baroda customer, especially from potentially affected branches, should treat this as an active risk and not a rumour to wait out.

This story will keep developing as the forensic investigation, RBI’s response, and CERT-In’s involvement become clearer. What won’t change is the basic advice: stay sceptical of anyone who calls claiming to be your bank, never install unknown APKs, and never share an OTP no matter how much the caller already seems to know.

To stay ahead, businesses must adopt proactive, intelligence-driven security strategies that simulate real-world threats and continuously validate their defenses. With Threatsys , organizations can build a resilient and future-ready security framework—ensuring their systems remain protected in an increasingly connected world.

 
Contact US Threatsys
 
 

Stay secure, Stay aware with Threatsys.

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *