Bank of Baroda Confirms Email Breach, 1TB Data Allegedly Leaked on Dark Web
India's second-largest public sector bank says core systems remain secure after employee account compromise triggered forensic probe and cyber insurance claim.
Bank of Baroda has confirmed a data breach stemming from the compromise of an employee's email account, as approximately one terabyte of sensitive information appeared on dark web marketplaces late last week.
The incident, first flagged around July 24-25, 2026, prompted the bank to file a preliminary cyber insurance claim under its ₹750 crore coverage with National Insurance as the lead insurer. In an official statement, the bank said: "The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The Bank's core banking systems were not accessed and continue to remain secure."
The breach has drawn attention to a persistent vulnerability in enterprise security: even when core infrastructure remains intact, compromised credentials can expose significant volumes of sensitive data. A comprehensive forensic investigation is underway, and the bank is coordinating with relevant authorities including the Indian Computer Emergency Response Team (CERT-In).
According to listings on dark web monitoring site ransomware.live, the leaked dataset may contain customer records and internal documents. Some reports cite figures between 100,000 and 300,000 customer account forms, though the bank has not confirmed the specific types of data accessed. Multiple outlets reported the total volume at approximately 1TB, though estimates vary between 700GB and 1TB across sources.
Cybersecurity researchers have tentatively linked the breach to a hacking group called TripleX, which was previously associated with an incident at Bank Negara Indonesia in mid-2026. However, no group has officially claimed responsibility for the Bank of Baroda incident, and assertions that the attack was motivated by weak password policies remain uncorroborated.
The timing is significant for India's public banking sector, which has faced increased scrutiny over cybersecurity preparedness following a string of incidents targeting financial institutions. Bank of Baroda, with over 5,000 domestic branches and presence in 25 countries, serves millions of retail and corporate customers.
For customers, the primary risk centers on potential identity theft if KYC documents such as Aadhaar details were among the compromised materials. The bank has not issued specific guidance to account holders beyond its initial statement, and it remains unclear whether affected individuals will be notified directly once the forensic review concludes.
Security experts note that email-based breaches often bypass technical defenses through social engineering or credential theft, making employee training and multi-factor authentication critical controls. The incident underscores that securing perimeter defenses means little if individual access points remain vulnerable to compromise.