Bank of Baroda Data Breach Claim: 1TB Leak Allegedly Exposes Customer Account Details and Aadhaar

Bank of Baroda could be facing a fresh security scare after a threat actor allegedly claimed to have breached the bank's systems and put around 1TB of sensitive data up for free on the dark web. The alleged data includes personal and corporate banking details such as Aadhaar numbers, names, and loan records from multiple branches across India.

Bank of Baroda (Photo Credit: Wikipedia)

Bank of Baroda could be facing a fresh security scare after a threat actor allegedly claimed to have breached the bank's systems and put around 1TB of sensitive data up for free on the dark web. The alleged data includes personal and corporate banking details such as Aadhaar numbers, names, and loan records from multiple branches across India. At the time of writing, Bank of Baroda has not publicly commented on the allegations, and there has been no confirmation from CERT-In or the Reserve Bank of India either.

X User Claims 1TB Of Bank Of Baroda Data Leaked

The claims were first flagged on X by Srikanth Lakshmanan, a software engineer and founder of CashlessConsumer, who tagged Bank of Baroda, the RBI and the government's cybersecurity awareness handle Cyberdost while urging authorities to investigate. Srikanth wrote on X, "Root folder of the data dump of @bankofbaroda #Databreach by threat actor. More verification links in the thread. The link is live. This is SOS @Cyberdost @RBI."

His post also included screenshots and a link to another X account, Dark Web Intelligence, which claimed a threat actor had published samples of the alleged data along with download links. The account posted, "India, Threat Actor Claims 1 TB Bank of Baroda Data Leak."

Hacker Allegedly Leaks 1TB Sensitive Data On Dark Web

What The Alleged Leaked Data Contains

According to the claims, the leaked information allegedly covers savings and current account records, loan data, NetBanking user details, NRI and corporate banking service records, customer support material, and branch or ATM-related records. The sample files reportedly include customer forms containing identity details, contact information and account-related data, though the source of the data and the method used to obtain it have not been disclosed. Are Public Claude AI Shared Chats And Sensitive Data Exposed On Google? Here's Truth Behind Users' Claims.

Speaking to India Today Tech, Srikanth said, "It's a cyber disaster." He added that he was able to verify the documents shared online, saying, "I was able to initially verify the documents and have found a range of internal documents of the bank. This includes branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country."

In a separate post, Srikanth said the leaked files went beyond standard KYC documentation. He wrote, "More sample data. Goes beyond KYC docs. Tonnes of internal audit data available. Each of it contains account opening forms - with names, photo, UID etc." Data Breach 2026: 149 Million Login Credentials for Gmail, Facebook and Binance Exposed Online; Cybersecurity Researcher Unsecured Database.

Who Is Behind The Alleged Breach

No hacker or group has publicly claimed responsibility for the breach so far. However, Srikanth believes a relatively new hacking group called TripleX may be behind the attack. He said, "The attacker, TripleX, who was previously involved in an Indonesian bank, has made the entire dataset publicly available on a tor site."

According to Srikanth, the breach was first spotted on Saturday, July 25, by dark web tracking site ransomware.live. In May this year, TripleX had allegedly breached one of Indonesia's largest state-owned banks, PT Bank Negara Indonesia, stealing around 2TB of data that included contracts, personal identification details, financial transaction histories and internal banking documents.

Bank Of Baroda's Security History

Bank of Baroda's internal systems have not seen a confirmed recent breach. However, in September 2025, cybersecurity firm UpGuard reported that an exposed third-party cloud database contained over 2,73,000 Indian banking records, of which around 6,000 were linked to Bank of Baroda.

Growing Concerns Over Banking Sector Cybersecurity

The latest allegations come amid heightened concern over cybersecurity threats in the banking sector. Advanced AI models had already prompted alarm among Indian authorities earlier this year, with the finance ministry asking financial institutions to implement proper safeguards following concerns raised over AI-related security risks.

Until an official investigation is completed and either Bank of Baroda or regulatory authorities issue a statement, the alleged breach and the authenticity of the leaked data remain unverified.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (India Today), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Jul 27, 2026 11:43 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now