Key Facts
- Incident Date: Data appeared on dark web on July 25, 2026
- Alleged Scale: 700 GB to 1 TB of data posted by threat actor
- Affected Records: Application forms for 100,000–300,000 individual customers
- Root Cause: Compromise of a single employee’s email account
- Data Exposed: Aadhaar details, PAN numbers, account-opening forms, loan records, branch audit files, internal communications
- Scope: Files from 1,088 branches across almost every state
- Threat Actor: Hacking group TripleX (previously linked to Bank Negara Indonesia breach)
- Bank’s Response: Forensic investigation initiated; RBI and CERT-In coordinated; cyber insurance claim filed
- Core Systems: Bank confirms core banking systems were not accessed and remain secure
- Fraud Status: No confirmed reports of identity theft or monetary siphoning to date
- Regulatory Status: RBI and CERT-In have not issued public statements
- Customer Base: 183 million customers
Direct Answer
Bank of Baroda suffered a major cybersecurity breach in late July 2026, with the hacking group TripleX allegedly leaking data containing application forms for an estimated 100,000 to 300,000 customers—amounting to 700 GB to 1 TB of internal and customer information—onto the dark web.
The state-run lender confirmed the incident on July 27, tracing the breach to a compromised employee’s email account, which resulted in unauthorised access to certain data. The bank has explicitly stated that its core banking systems were not accessed and remain completely secure, and that deposits and transactions are safe.
The leaked data, verified by cybersecurity researcher Srikanth L of Cashless Consumer, includes customer names, photographs, Aadhaar details, PAN card numbers, savings and current account records, loan documents, internal audit files, and branch-specific documents. Neither the Reserve Bank of India (RBI) nor CERT-In has issued a public statement as of the current date.
There are no confirmed reports of identity theft or monetary fraud stemming directly from this leak. The bank has implemented containment protocols, launched an ongoing forensic investigation, and is coordinating with regulatory authorities. For the bank’s 183 million customers, the primary risk is not direct financial loss but identity theft, phishing, and fraud using the exposed personal information.
In this article:
- [What Happened: The Breach and Its Timeline]
- [What Data Was Exposed]
- [The Threat Actor: TripleX]
- [Bank of Baroda’s Response]
- [Regulatory Response and Fraud Status]
- [Why This Matters: From Data Leak to Identity Theft]
- [What Customers Must Do Now]
- [FAQ]
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
What Happened: The Breach and Its Timeline
On the night of July 25, 2026, a threat actor posted a large cache of data on the dark web, claiming it belonged to Bank of Baroda. The data was advertised on dark web monitoring platform ransomware.live.
Key dates:
- July 24, 2026: Dark web listing appeared, claiming dataset contained 100,000–300,000 customer forms
- July 25, 2026: Data appeared on dark web site
- July 27, 2026: Bank of Baroda issued official statement confirming the incident
- July 27, 2026: Bank filed exchange disclosure
Cybersecurity researcher Srikanth L, founder of Cashless Consumer, verified sample files and confirmed the data was still accessible. The compromised data spans branches in Haryana, Uttar Pradesh, Maharashtra (including Greater Mumbai and Nagpur), Karnataka (Mysore), Madhya Pradesh (Bhopal), Rajasthan (Jaipur), and Kerala.
The files appeared to have been last accessed or copied around June 23-24, 2026.
What Data Was Exposed
According to cybersecurity researchers and verified sample files, the leaked data includes:
Identity Data
- Customer names
- Photographs
- PAN card numbers
- Aadhaar details
- Account-opening forms (100,000–300,000 forms estimated)
Financial Records
- Savings and current account numbers
- NetBanking user data
- Loan applications and documents
Corporate Records
- Internal audit files
- Branch audit reports
- Customer support documents
- Non-resident Indian (NRI) services records
- Vigilance investigation records
Infrastructure Records
- Branch-specific documents
- ATM-related information
The Threat Actor: TripleX
The hacking group TripleX has claimed responsibility for the attack. According to dark web monitoring platform Ransomware.live, TripleX’s listing dated July 24 claimed the dataset contains between 100,000 and 300,000 customer forms.
TripleX is not a new player. The group was previously linked to a cyberattack on Indonesia’s state-owned Bank Negara Indonesia in May 2026, where approximately 2 TB of data was stolen, including contracts, personal identification details, financial transaction histories, and internal banking documents.
The group made the Bank of Baroda dataset publicly available on a Tor site.
Bank of Baroda’s Response
Official Statement
Bank of Baroda issued a statement on July 27 confirming the incident:
“The incident involved compromise of an employee’s email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The Bank’s core banking systems were not accessed and continue to remain secure.”
Key Actions Taken
- Containment: The bank isolated internet-connected computers at its headquarters after detecting signs of the breach
- Forensic Investigation: A comprehensive forensic investigation has been initiated and is ongoing
- Regulatory Coordination: The bank is working behind the scenes with RBI and CERT-In
- Cyber Insurance Claim: The bank has filed a preliminary claim under its cyber insurance policy
- Exchange Disclosure: The bank informed stock exchanges under SEBI Listing Regulations
- Independent Assessment: An independent CERT-In empanelled agency has been engaged to assess the nature and extent of the alleged compromise
Cyber Insurance Details
Bank of Baroda’s cyber insurance programme reportedly covers approximately ₹750 crore, with an annual premium of around ₹6 crore involving multiple domestic insurers and reinsurers. The claim has been lodged as a notice of loss, allowing insurers to begin assessing the incident while forensic investigations are underway.
The Bank’s Position
The bank described the incident as a “potential business email compromise” that is “not expected to have any material impact on the Bank’s operations, financial performance or business continuity.”
Regulatory Response and Fraud Status
RBI and CERT-In Statements
As of the current date, neither the Reserve Bank of India (RBI) nor CERT-In has issued an official public statement or regulatory directive regarding the Bank of Baroda data breach. The bank has confirmed it is actively coordinating behind the scenes with these regulatory authorities.
Forensic Investigation Status
The forensic audit is ongoing and currently active. Bank of Baroda has implemented primary containment protocols to lock down the compromised email network but has not yet published its formal investigative findings regarding the full scope of the breach.
Reports of Financial Fraud
There are currently no confirmed reports of actual identity theft or monetary siphoning stemming directly from this dark web leak. Because the bank’s core banking systems were completely bypassed, customer funds and transaction channels remain secure.
However, the absence of confirmed fraud does not mean the risk is absent. Exposed personally identifiable information can be exploited for identity theft, phishing, and other frauds—potentially weeks, months, or even years after the initial leak.
Why This Matters: From Data Leak to Identity Theft
What This Is Not
This is not a bank account hack. Bank of Baroda’s core banking systems—which manage deposits, withdrawals, fund transfers, and other banking transactions—were not accessed.
To actually move money out of an account, a fraudster would need login passwords, transaction PINs, OTPs tied to the registered phone number, or biometric access. A database leak alone does not provide these.
What This Is
This is a privacy and identity fraud problem. Exposed personally identifiable information—Aadhaar numbers, PAN cards, account numbers, loan documents, photographs—can be used for:
- Identity theft: Opening new accounts, applying for loans, filing fraudulent tax returns in the victim’s name
- Phishing and vishing: Targeted scams using real data to gain trust—fraudsters can call with accurate details to bypass suspicion
- Account takeover: Using leaked information to answer security questions and reset passwords
- Synthetic identity fraud: Combining real and fake data to create new identities
The Scale of Risk
- 183 million Bank of Baroda customers
- 1,088 branches affected
- 100,000–300,000 customer onboarding forms exposed
- Data still accessible on the dark web
What Customers Must Do Now
The bank has not yet asked customers to reset passwords or take specific action. However, cybersecurity experts recommend immediate precautions.
Immediate Actions
- Lock Your Aadhaar Biometrics: Use the official mAadhaar app or the UIDAI portal to lock your biometrics. This prevents anyone from using your Aadhaar identity for unauthorised authentications.
- Reset Banking Credentials: Change your Bank of Baroda Net Banking password and mobile banking PIN immediately.
- Enable Transaction Alerts: Ensure SMS and email alerts are activated for all transactions. Review account statements regularly for unrecognised activity.
- Monitor Credit Reports: Check for unauthorised loan applications or new accounts opened in your name.
- Be Suspicious of Communications: Beware of phone calls, emails, or messages claiming to be from Bank of Baroda. The bank will never ask you to share OTPs, passwords, PINs, or CVV codes. Verify any request by calling the official bank number.
- Access Banking Services Safely: Use only the official Bank of Baroda website or mobile app. Avoid clicking on links in emails or messages.
- Enable Multi-Factor Authentication: Wherever available, enable multi-factor authentication for additional security.
If You Suspect Fraud
- Call the National Cyber Crime Helpline at 1930 immediately
- File a complaint at cybercrime.gov.in
- Notify your bank branch
- Document all communications and transaction records
FREQUENTLY ASKED QUESTIONS (FAQ)
Q: How many customers were affected by the Bank of Baroda data leak?
Ans: The leaked dataset contains application forms for an estimated 100,000 to 300,000 individual customers out of the bank’s 183 million customer base.
Q: What specific types of data were exposed on the dark web?
Ans: Customer names, photographs, PAN numbers, Aadhaar details, account-opening forms, loan records, internal audit reports, and branch documents.
Q: Has any financial fraud or monetary siphoning been reported?
Ans: As of late July 2026, there are no confirmed reports of actual identity theft or monetary siphoning stemming directly from the leak.
Q: What steps should customers take immediately?
Ans: Lock Aadhaar biometrics via mAadhaar, reset NetBanking credentials, enable transaction alerts, and monitor credit reports for unauthorized activity.
What happened in the Bank of Baroda data breach?
A threat actor allegedly leaked 700 GB to 1 TB of customer and internal data on the dark web. The breach originated from a compromised employee’s email account.
When did the breach occur?
The data appeared on the dark web on July 25, 2026. The bank confirmed the incident on July 27, 2026.
How many customers are affected?
The leaked dataset contains application forms for an estimated 100,000 to 300,000 individual customers. The bank has 183 million total customers.
What data was exposed?
Exposed data includes Aadhaar details, PAN numbers, customer photographs, account-opening forms, savings and current account records, loan documents, NetBanking user data, internal audit files, and branch- and ATM-related information.
Is my money safe?
The bank states that core banking systems were not accessed and remain secure. Deposits and transactions are not directly at risk.
Has any financial fraud been reported?
As of the current date, there are no confirmed reports of actual identity theft or monetary siphoning stemming directly from this leak.
What has RBI or CERT-In said?
Neither RBI nor CERT-In has issued an official public statement or regulatory directive as of the current date. The bank is coordinating with them behind the scenes.
Who is responsible for the breach?
The hacking group TripleX has claimed responsibility. The group was previously linked to a 2 TB breach of Bank Negara Indonesia.
What has the bank done?
The bank has implemented containment measures, launched an ongoing forensic investigation, coordinated with regulatory authorities, and filed a cyber insurance claim.
Should I change my passwords?
Yes. Cybersecurity experts recommend changing your Bank of Baroda Net Banking password and mobile banking PIN immediately.
What should I do if I receive a call claiming to be from Bank of Baroda?
Be suspicious. The bank will never ask for OTPs, passwords, PINs, or CVV codes. Verify any request by calling the official bank number. Ignore unsolicited calls, emails, or messages seeking banking credentials.
How do I lock my Aadhaar biometrics?
Use the official mAadhaar app or the UIDAI portal to lock your biometrics. This prevents unauthorised use of your Aadhaar identity.
Is there any insurance for my deposits?
Deposits in Indian banks, including Bank of Baroda, are insured up to ₹5 lakh per depositor under the DICGC scheme.
KNOWLEDGE CHECK QUIZ
Q: What was the primary root cause of the Bank of Baroda data breach?
Ans: The compromise of a single employee’s email account, leading to unauthorized access and data exfiltration.
Q: How much data was allegedly leaked by the TripleX hacking group?
Ans: Between 700 GB and 1 TB of internal and customer data.
Q: Were core banking systems affected during the incident?
Ans: No. Bank of Baroda confirmed that core banking systems were not accessed and remain secure.
Q: What is the primary risk facing customers whose data was leaked?
Ans: Identity theft, phishing, vishing, and synthetic identity fraud using exposed Aadhaar and PAN details.
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances
Author:
Adv. Shoeb Hakim
Author Bio (for schema markup):
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybercrime, data protection, financial fraud, and privacy law.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Cybersecurity | Data Breach | Banking | Privacy Law
Article Tags:
Bank of Baroda, data breach, cyberattack, dark web, employee email compromise, TripleX, Aadhaar leak, customer data, identity theft, RBI, CERT-In, cyber insurance, Adv Shoeb Hakim
#AdvShoebHakim #BankOfBaroda #DataBreach #TripleX #CyberSecurity #IdentityTheft #DigitalForensics #BankingCompliance #LegalComplianceIN #Vakilverse



Leave a Reply