Bank of Baroda Data Breach: What Account Holders Need To Do

Bank of Baroda has confirmed that an employee email account was compromised, allowing unauthorised access to certain customer data. While the bank says its core banking systems remain secure, experts advise customers to change passwords, enable transaction alerts, avoid phishing links and monitor credit reports as regulators examine the incident.

Bank of Baroda (Photo Credits: PTI)

Bank of Baroda has confirmed that an employee email account was compromised, leading to unauthorised access to certain customer data. While the state-run lender said its core banking systems remain secure and that a forensic investigation is underway after initial containment measures were implemented, the incident has raised questions about possible regulatory action and the steps customers should take to protect themselves.

The confirmation shifts the focus from the breach itself to its potential consequences. Regulators are expected to examine whether the bank complied with cybersecurity and data protection requirements, while cybersecurity experts are urging customers to take immediate precautions to safeguard their personal and financial information. Bank of Baroda Launches Forensic Probe After Alleged Data Leak; Says Core Banking Systems Secure.

Bank of Baroda Data Breach: Regulators May Examine Compliance

The Reserve Bank of India (RBI) is expected to review whether Bank of Baroda adhered to the cybersecurity and risk management framework applicable to banks.

Depending on the findings of the forensic investigation, the central bank could direct the lender to strengthen its security controls, improve internal processes or take other supervisory measures. If regulatory violations are established, the RBI also has the authority to impose penalties under applicable banking laws. Bank of Baroda Clarifies Security Incident After Alleged 1TB Data Leak Claims on Dark Web.

India's Computer Emergency Response Team (CERT-In) may also examine whether the incident was reported within the prescribed timeline and whether the bank followed the required cyber incident response procedures. The incident could additionally attract scrutiny under the Digital Personal Data Protection (DPDP) Act.

Experts Highlight Possible Penalties

Sudiptaa Paul Choudhury, Chief Marketing Officer at QNu Labs, said the DPDP Act provides for significant penalties in cases involving inadequate security safeguards or failure to report data breaches.

"This lands right in the middle of a live regulatory shift in India. While the Data Protection Board is already operational, the penalty machinery formally switches on this November."

She noted that the DPDP Act allows penalties of up to ₹250 crore for failing to implement reasonable security safeguards and up to ₹200 crore for failing to report a data breach.

According to Choudhury, CERT-In's six-hour breach reporting requirement already applies, while Section 43A of the Information Technology Act may expose organisations to compensation claims for negligent handling of sensitive personal data. RBI cybersecurity regulations also require banks to meet additional reporting and remediation obligations.

However, experts emphasise that no regulatory penalty is automatic. Any action will depend on the outcome of the forensic investigation and the assessment by relevant authorities.

What Should Customers Do Now?

Cybersecurity experts advise customers not to wait for the investigation to conclude before taking preventive measures. "Don't wait for confirmation, act like it's real," said Choudhury.

Customers are advised to:

  • Change net banking and mobile banking passwords immediately.
  • Enable transaction alerts if they are not already active.
  • Carefully review every banking notification received.
  • Avoid clicking links in SMS messages or emails claiming to be from Bank of Baroda, as phishing attempts often increase following publicised data breaches.

Choudhury warned: "Every breach headline triggers a wave of 'verify your KYC' phishing, so open the app directly or type the URL yourself instead."

If customers suspect their Aadhaar information may have been exposed, she recommends locking Aadhaar biometrics through the UIDAI website or the mAadhaar app. "It takes five minutes and shuts a door identity thieves love."

She also urged customers to monitor their credit reports in addition to their bank statements. "Leaked PII gets used to open loans and cards in your name, not just to empty your existing account."

Customers who notice suspicious transactions or believe their information may have been misused should immediately inform Bank of Baroda and report the incident through the National Cyber Crime Reporting Portal or by calling the cybercrime helpline 1930.

Bank of Baroda said the incident involved a compromised employee email account and resulted in unauthorised access to certain customer data. The bank stated that its core banking infrastructure remains secure and that it has initiated a forensic investigation after implementing initial containment measures. Authorities are expected to determine whether the lender complied with applicable cybersecurity and data protection requirements.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (India Today), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Jul 28, 2026 11:16 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now