AI Generated

Bank of Baroda Probes Alleged 1TB Data Leak After Claims Aadhaar and Customer Records Were Posted on the Dark Web

Bank launches forensic investigation as researchers flag alleged customer data leak amid rising cybersecurity concerns nationwide.

Supported by

Bank of Baroda (BoB), one of India’s largest public sector banks, is investigating claims that a threat actor has leaked nearly 1TB of sensitive banking data on the dark web, raising fresh concerns about cybersecurity in the country’s financial sector.

The alleged breach, first flagged by cybersecurity researchers monitoring ransomware forums on July 25, reportedly includes customer names, Aadhaar numbers, account details, loan records, NetBanking information, corporate banking files and internal bank documents.

Software engineer and CashlessConsumer founder Srikanth Lakshmanan, who examined sample files shared online, described the incident as “a cyber disaster” and said he was able to verify several internal documents, including branch audits, loan appraisal files and customer application forms from multiple branches across India.

Media Reporters, citing a source familiar with the matter, reported that Bank of Baroda has launched a forensic investigation and is examining the authenticity of the leaked material, though it has not confirmed that customer data has been compromised. Neither the Reserve Bank of India (RBI) nor the Indian Computer Emergency Response Team (CERT-In) had officially confirmed the breach or announced regulatory action at the time of publication.

Cybersecurity experts have stressed that while the alleged leak does not necessarily mean customer funds are immediately at risk, exposed personal information could increase the chances of phishing, identity theft and financial fraud, prompting calls for customers to strengthen their account security while investigations continue.

Researchers Flag Massive Leak

According to cybersecurity researchers and media reports, the alleged breach surfaced after a dataset claimed to contain approximately 1TB of Bank of Baroda information was uploaded to a Tor-based dark web portal.

The files reportedly include savings and current account records, Aadhaar details, corporate banking documents, NRI banking records, customer support material, internal audit reports, vigilance investigations, ATM-related documents and bobWorld audit files.

Srikanth Lakshmanan said the leak was initially detected through ransomware monitoring platform ransomeware.live, after which he reviewed sample documents published by the threat actor. “I was able to initially verify the documents and have found a range of internal documents of the bank,” he told India Today Tech, adding that the files included branch audits, loan appraisal reports, internal communications and customer application forms spanning multiple Bank of Baroda branches.

He described the incident as “a cyber disaster.” However, researchers have also emphasised that only portions of the sample data have been independently examined, and there is no official confirmation that the entire claimed 1TB dataset is genuine or that every category of customer information has been compromised.

Other media sources reported that preliminary findings suggest investigators are examining whether the breach may have originated from a compromised email system, although the exact cause has not yet been established.

Bank of Baroda has acknowledged that it is conducting a forensic audit but has not publicly confirmed any breach of customer systems. As of now, neither RBI nor CERT-In has issued an official statement confirming the authenticity or scale of the alleged leak.

Growing Cybersecurity Concerns

The alleged attack comes amid increasing concern over cyber threats targeting financial institutions in India and globally. While no hacker has formally claimed responsibility through conventional ransomware channels, cybersecurity researcher Srikanth Lakshmanan believes the attack could be linked to a relatively new hacking group known as TripleX, which was previously associated with the alleged theft of around 2TB of data from Indonesia’s state-owned PT Bank Negara Indonesia.

Although this attribution has not been independently verified, researchers say similarities in the publication methods warrant further investigation. Cybersecurity experts have also cautioned that a data leak does not automatically translate into unauthorised access to customer funds, as modern banking systems rely on multiple safeguards such as OTP authentication, transaction passwords, UPI PINs, device verification and fraud monitoring.

Nevertheless, the exposure of personal information could enable criminals to launch phishing campaigns, fake KYC requests, impersonation scams and identity theft attempts. Customers have therefore been advised to update banking passwords, enable two-factor authentication, closely monitor account activity and avoid sharing confidential banking credentials over phone calls, text messages or social media.

The incident has also revived discussions around an earlier cybersecurity issue involving Bank of Baroda. In September 2025, cybersecurity firm UpGuard reported that an exposed third-party cloud database contained over 273,000 Indian banking records, around 6,000 of which were linked to Bank of Baroda.

That exposure was attributed to a third-party service rather than the bank’s own systems, highlighting broader concerns around supply-chain security and third-party vendors. The latest allegations have also triggered widespread discussion across social media platforms, where users have expressed concern over the possible exposure of Aadhaar-linked financial records while urging fellow customers to remain cautious against phishing attempts.

The Logical Indian’s Perspective

As banking services become increasingly digital, cybersecurity is no longer merely a technical concern it is fundamental to public trust. Allegations of a data breach involving a major public sector bank underline the importance of timely disclosures, transparent investigations and strong digital safeguards that protect citizens’ personal and financial information. Equally important is responsible reporting and public communication.

Until official investigations establish the facts, it is essential to distinguish verified information from unconfirmed claims while encouraging customers to take sensible precautionary measures without creating unnecessary panic. Incidents such as these also highlight the need for continuous investment in cyber resilience, independent security audits, stronger vendor oversight and greater public awareness about online fraud.

Also read: How Mirabai Chanu Created History With a Third Consecutive CWG Gold and Record-Breaking 190kg Lift

#PoweredByYou We bring you news and stories that are worth your attention! Stories that are relevant, reliable, contextual and unbiased. If you read us, watch us, and like what we do, then show us some love! Good journalism is expensive to produce and we have come this far only with your support. Keep encouraging independent media organisations and independent journalists. We always want to remain answerable to you and not to anyone else.

Featured

Amplified by

Amazon Prime

For Two Nights in June, Mumbai’s Sea Link and Asiatic Library Wore Light Like They’ve Never Worn It Before

Amplified by

Ministry of Road Transport and Highways

From Risky to Safe: Sadak Suraksha Abhiyan Makes India’s Roads Secure Nationwide

Recent Stories

Kolkata’s First Singaporean Cafe Creates Dignified Employment And Hope For Trafficked Women

‘We Can Protest While Dancing’: Saurav Das Defends CJP Celebration Videos After Pradhan’s Exit

India Summons Ukraine Ambassador After Merchant Ship Carrying 4 Indians Comes Under Attack

Contributors

Writer : 
Editor : 
Creatives :