Bank of Baroda Allegedly Hit by Massive Data Breach as 1 TB of Banking Records Surface Online

The CyberSec Guru

Updated on:

Bank of Baroda data breach

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

Update: Bank of Baroda Database Allegedly Offered for Sale

A new and separate claim has now surfaced on an underground forum, where a threat actor is allegedly offering for sale a database they claim is associated with Bank of Baroda.

According to the newly surfaced listing, the seller claims to possess approximately 1.5 billion “sensitive files”, allegedly containing customer information, financial records, certificates, and other bank-related data. The database is reportedly being offered at a negotiable price, with prospective buyers instructed to contact the seller through the Session messaging platform.

The claim requires significant caution. The forum account appears to be newly created and has no established reputation, while the listing itself does not provide sufficient evidence to independently establish either the authenticity or the scale of the alleged dataset. In particular, the extraordinary claim of 1.5 billion files has not been independently verified, and there is currently no evidence in the listing itself proving that the advertised data originated from Bank of Baroda.

This development should also be distinguished from the previously reported approximately 1 TB Bank of Baroda data leak discussed below. The relationship, if any, between the two claims is currently unknown. There is no reliable evidence at this stage showing that the newly advertised database is part of the earlier dataset, represents a separate compromise, or even contains genuine Bank of Baroda information.

The new listing therefore adds another potential threat-intelligence lead to the ongoing incident, but it should not be interpreted as confirmation of an additional 1.5-billion-file breach. The unusually large figure, the lack of seller history, and the absence of independently verifiable samples make further validation particularly important.

We will update this article if credible evidence emerges confirming the dataset’s origin, contents, or relationship to the previously reported Bank of Baroda leak.

Update: On Monday, July 27, the state-owned Bank of Baroda (BoB) acknowledged a security incident where unauthorized individuals gained access to “certain data.” This incident originated from a compromised employee email account, as stated by BoB.

Original Article Continues Below

BoB communicated on X that “The matter was promptly identified, and immediate containment measures were implemented.” Although the bank did not provide extensive details regarding the extent of the data breach or the specific types of data accessed by the unauthorized party, it assured that its core banking systems were not affected and remain secure.

Statement from Bank of Baroda

A threat actor has published what it claims is approximately 1 TB of data associated with Bank of Baroda, one of India’s largest public sector banks. The leaked dataset allegedly contains thousands of internal documents alongside customer information spanning retail, corporate, and digital banking operations. If authenticated, the incident could rank among the largest publicly exposed datasets involving an Indian financial institution.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

At the time of writing, however, Bank of Baroda has not publicly confirmed the alleged breach, and there has been no official confirmation from CERT-In or the Reserve Bank of India (RBI). While multiple researchers have verified the presence of internal-looking documents and directory listings, the claimed size of the dataset, the attack method, and the full scope of affected records remain independently unverified.

Bank of Baroda Logo
Bank of Baroda Logo

What Has Been Published?

The alleged leak first gained attention after researchers and dark web monitoring platforms identified a Tor-hosted dataset containing what appears to be Bank of Baroda’s internal file hierarchy. Security researcher Srikanth Lakshmanan, founder of CashlessConsumer, stated that he verified numerous documents within the archive and described the incident as a significant cybersecurity event.

BoB Data Breach Details
BoB Data Breach Details

According to the available samples, the exposed material goes well beyond isolated customer documents. The directory listings appear to contain branch audit reports, loan appraisal files, internal communications, vigilance investigations, bob World audit documentation, customer onboarding records, and operational documents from branches across India. Sample files reportedly include customer application forms containing names, photographs, Aadhaar numbers, contact information, account opening documents, and loan-related paperwork.

Researchers also observed documentation related to firewall reviews, vulnerability assessments, audit findings, compliance reports, and branch-level operational records. While only portions of the dataset have been publicly examined, the breadth of the exposed directory structure suggests that the alleged compromise may involve an internal document repository rather than a narrowly scoped database.

Directory Structure Suggests Large Internal File Repository

Screenshots shared by researchers show what appears to be an indexed directory under a Bank of Baroda domain containing numerous folders named after regional offices, audit teams, business units, inspections, and operational departments. The structure includes directories associated with internal audits, customer documentation, branch inspections, digital banking, corporate banking, and regional administration.

Independent analysis of the published directory structure identified:

  • 62 top-level business or regional directories
  • More than 2,600 subdirectories
  • Approximately 15,700 indexed files

Most of the indexed documents are PDFs, followed by spreadsheets, ZIP archives, Word documents, JPEG images, and Excel binary workbooks. Although file counts alone cannot determine the volume of exposed information, the distribution indicates a document repository rather than a single customer database.

Several folders reportedly contain thousands of documents each, including audit documentation, branch records, customer portfolios, and bob World-related audit material.

What Data Appears to Be Included?

Based on publicly shared samples and researchers’ analysis, the alleged dataset may include:

  • Customer account opening forms
  • Aadhaar details
  • Customer photographs
  • Savings and current account documentation
  • Loan appraisal documents
  • Corporate banking records
  • NRI banking documentation
  • NetBanking-related records
  • Customer support documentation
  • ATM and branch operational files
  • Internal audit reports
  • Vigilance investigation documents
  • bob World audit documentation
  • Security and compliance documents

The threat actor claims the complete archive totals roughly 1 TB, although that figure has not been independently verified.

Importantly, the existence of sample files does not automatically confirm that every claimed category or every customer record has been compromised. Threat actors have historically exaggerated breach sizes or mixed genuine internal documents with unrelated material to increase pressure on victims.

Technical Assessment

One of the more concerning aspects of the alleged breach is not simply the potential exposure of customer information, but the apparent presence of internal security documentation.

Researchers report that the dataset includes vulnerability assessment and penetration testing (VAPT) reports, firewall review documentation, audit findings, and security assessment material. If authentic, these documents could provide attackers with valuable insight into an organization’s infrastructure, previously identified weaknesses, remediation status, and network architecture.

Unlike customer data, which is typically valuable for fraud or identity theft, internal security documentation can significantly reduce the effort required for future attacks. VAPT reports often describe discovered vulnerabilities, affected systems, severity ratings, recommended mitigations, and evidence collected during testing. Firewall review documents may reveal network segmentation, rule configurations, security zones, or administrative practices.

Even if individual vulnerabilities have already been remediated, such documentation can help threat actors understand how an enterprise environment is designed, identify recurring operational patterns, and prioritize future intrusion attempts.

The published directory hierarchy also resembles an enterprise document-sharing platform rather than a structured production database. The large number of PDFs, Office documents, audit files, and departmental folders is consistent with centralized document repositories commonly used for collaboration and compliance.

At present, however, there is no public evidence confirming whether the alleged data originated from an internal SharePoint deployment, another enterprise document management platform, or a different storage environment.

Who Is Behind the Alleged Attack?

Researchers attribute the leak to a relatively new threat actor known as Triple X, although this attribution remains based primarily on the group’s own claims and similarities with previous activity.

BoB Alleged Data Breach
BoB Alleged Data Breach

According to publicly available reporting, Triple X previously claimed responsibility for a breach involving Indonesia’s state-owned Bank Negara Indonesia (BNI), where the group alleged it had stolen roughly 2 TB of customer and internal banking data.

In the Bank of Baroda case, the same actor has reportedly published both sample documents and a browsable directory listing through its Tor-based leak site rather than limiting disclosure to screenshots or promotional samples.

The group has also claimed that the initial compromise resulted from a “weak password.” No independent evidence supporting that claim has been published, and it should be treated solely as the threat actor’s assertion until confirmed through an official investigation.

No Official Confirmation Yet

Despite the volume of publicly circulating material, several critical questions remain unanswered.

Bank of Baroda has not issued an official statement confirming or denying the reported breach. Likewise, CERT-In and the Reserve Bank of India had not publicly confirmed the incident at the time of publication.

Without an official forensic investigation, it remains unknown:

  • how the alleged attackers obtained the data,
  • whether production banking systems were compromised,
  • whether the repository originated from a third-party environment,
  • whether the published data represents the complete dataset, or
  • how many customers may ultimately be affected.

These questions are likely to determine the true scope and impact of the incident.

Previous Security Incidents

Although this alleged breach is unrelated to earlier incidents, Bank of Baroda has previously appeared in cybersecurity reporting.

In September 2025, UpGuard disclosed an exposed third-party cloud database containing more than 273,000 Indian banking records, including approximately 6,000 entries associated with Bank of Baroda. That exposure originated from a third-party environment rather than the bank’s internal infrastructure.

Separately, in 2023, the Reserve Bank of India directed the bank to suspend onboarding of new customers through the bob World application following supervisory concerns related to irregular customer onboarding practices. That incident involved operational and compliance issues rather than a cyberattack.

Neither event establishes a connection to the current allegations.

Potential Impact

If the leaked material proves authentic, the consequences extend well beyond identity theft.

Customer records containing personally identifiable information (PII) can facilitate phishing, financial fraud, social engineering, and account takeover attempts. Internal audit documents may expose business processes, while loan records and corporate banking files could reveal commercially sensitive information.

Perhaps more concerning is the reported presence of internal security documentation. Such material could provide adversaries with a detailed understanding of an organization’s defensive posture, allowing future attacks to be tailored more effectively.

At this stage, however, there is no public evidence indicating that customer funds have been stolen or that banking operations have been disrupted.

What Customers Should Do

Until additional information becomes available, Bank of Baroda customers should remain alert for phishing emails, SMS messages, and phone calls requesting OTPs, passwords, or banking credentials. Customers should review account activity regularly, enable transaction alerts where available, and report any suspicious activity immediately through official banking channels.

It is also advisable to avoid relying on unsolicited messages referencing the reported breach, as threat actors frequently exploit high-profile incidents to launch phishing campaigns against concerned customers.

Conclusion

The Bank of Baroda incident has quickly become one of the most significant alleged banking data exposures reported in India this year. Publicly available samples appear to show genuine internal documents, customer forms, audit reports, and operational records, while researchers have verified that a large directory structure containing thousands of files is accessible through the threat actor’s leak site.

Nevertheless, several fundamental questions remain unresolved. The claimed 1 TB dataset, the alleged access method, the attribution to Triple X, and the full extent of affected customer data have not been independently confirmed by Bank of Baroda, CERT-In, or the RBI. Until official forensic findings are released, the incident should be treated as an ongoing investigation rather than a fully established compromise.

If the published material is ultimately authenticated, the breach would represent not only a substantial exposure of customer information but also a significant leak of internal operational and security documentation, underscoring the growing cybersecurity challenges facing the financial sector.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading