Bank of Baroda Investigates Alleged Data Breach After Hacker Claims Theft of 1TB Data

The CSR Journal Magazine

Bank of Baroda is facing allegations of a major cybersecurity breach after a threat actor claimed to have stolen more than 1TB of sensitive banking data and offered it for sale on the dark web. The alleged dataset is said to contain customer and corporate banking records, including Aadhaar details, loan documents and internal bank files.

The bank has not yet commented on the claims. At the time of publication, there was also no official confirmation from the Indian Computer Emergency Response Team (CERT-In) or the Reserve Bank of India (RBI) regarding the alleged breach.

Hacker Claims to Have Stolen Customer and Internal Data

According to reports, the threat actor claims the leaked data includes savings and current account records, loan information, NetBanking user details, NRI and corporate banking records, customer support material, and branch- and ATM-related documents.

The hacker has also uploaded sample files online to support the claim. Software engineer and CashlessConsumer founder Srikanth Lakshmanan shared screenshots of the alleged leaked documents on X, stating that the link hosting the sample data was active.

Speaking to India Today Tech, Lakshmanan described the incident as “a cyber disaster.”

India Today Tech reported that it had contacted Bank of Baroda for a response and would update the story once the bank issued an official statement.

Researcher Says Sample Documents Appear Genuine

Lakshmanan said the alleged breach was first identified on Saturday, July 25, by dark web monitoring platform ransomeware.live.

After examining the sample files, he said he was able to verify several of the documents, which allegedly included confidential internal bank records alongside customer information.

“I was able to initially verify the documents and have found a range of internal documents of the bank,” Lakshmanan told India Today Tech. “This includes branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country.”

TripleX Group Suspected Behind Alleged Attack

Although no hacking group has officially claimed responsibility for the incident, Lakshmanan believes a relatively new cybercriminal group known as TripleX may be behind the alleged breach.

He said, “The attacker – TripleX – who was previously involved in an Indonesian bank – has made the entire dataset publicly available on a tor site.”

TripleX was linked to a cyberattack on Indonesia’s state-owned PT Bank Negara Indonesia in May this year. According to the report, the group allegedly stole around 2TB of data, including contracts, personal identification records, financial transaction histories and internal banking documents.

Banking Sector Faces Growing Cybersecurity Threats

The alleged breach comes amid increasing concerns over cybersecurity risks facing financial institutions. Recent warnings have urged banks to strengthen digital security systems in response to evolving cyber threats and the growing sophistication of attacks.

While there has been no recent confirmed breach involving Bank of Baroda’s internal systems, cybersecurity firm UpGuard reported in September 2025 that an exposed third-party cloud database contained more than 2,73,000 Indian banking records, around 6,000 of which were linked to Bank of Baroda.

Authorities are yet to verify the authenticity of the latest claims. Until an official investigation is completed, the extent of the alleged breach and the accuracy of the hacker’s claims remain unconfirmed.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos