TechNewsReel
Live

Bank of Baroda Confirms Email Compromise After Hacker Claims 1TB Data Leak

India's second-largest public sector bank says core systems remain secure while forensic investigation underway.

TechNewsReel Newsroom · July 27, 2026

Bank of Baroda confirmed on July 27, 2026, that an employee email account was compromised, resulting in unauthorized access to certain data, following claims by a hacker that approximately 1TB of sensitive information from the bank was leaked on the dark web.

The breach was first spotted on July 25 by ransomware.live, a dark web tracking site. The hacker claims the data is available for free download, though the bank has not verified the volume or full extent of what was accessed.

Bank Response

In an official statement, Bank of Baroda said its core banking systems were not accessed and remain secure. The bank has initiated a comprehensive forensic investigation and is working with relevant authorities to assess the scope of the compromise.

The distinction between email system access and core banking infrastructure is critical. Core systems hold customer account balances, transaction histories, and loan records. Email compromise, while serious, typically exposes correspondence and attachments rather than direct financial account access.

What We Know

Bank of Baroda is one of India's largest public sector banks, serving millions of customers across the country. The institution has not publicly specified what data was accessed through the compromised email account, pending completion of the forensic investigation.

Multiple Indian news outlets reported the hacker's claim of 1TB in leaked data, but this figure originates from the attacker and remains unverified by independent analysis or the bank itself. Sample documents were reportedly shared on dark web forums, though their full authenticity has not been independently confirmed.

Broader Context

Cyberattacks targeting Indian financial institutions have increased in frequency, with attackers often seeking customer personally identifiable information and financial records to facilitate fraud or extortion. A breach affecting even email systems at a major state-run bank raises concerns about potential exposure of customer communications and attached documents.

A hacking group called Triplx X is suspected by some experts to be behind the attack, though no group has publicly claimed responsibility. The same group was previously linked to a May 2026 cyberattack on Indonesia's PT Bank Negara Indonesia, where approximately 2TB of data was stolen.

As of July 27, neither India's Computer Emergency Response Team (CERT-In) nor the Reserve Bank of India (RBI) had issued public statements on the incident.

What Customers Should Know

The bank has not issued specific guidance to customers beyond confirming the investigation is underway. Security experts typically recommend that customers of affected institutions monitor account statements for unusual activity, avoid clicking on suspicious emails claiming to be from the bank, and enable two-factor authentication where available.

The forensic investigation's findings will determine the actual scope of data exposure and whether customer notification is required under Indian data protection regulations.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.