Bank of Baroda Confirms Employee Email Hack, Up to 1TB of Customer Data Leaked
India's second-largest public sector bank says core systems remain secure after threat actor posted account records, Aadhaar numbers on dark web.
Bank of Baroda has confirmed a cybersecurity incident after a threat actor compromised an employee's email account and exfiltrated sensitive customer data that was subsequently leaked on the dark web.
The state-owned lender, India's second-largest public sector bank, said its core banking systems were not accessed and remain secure. However, approximately 700GB to 1TB of data was made available online for free, according to cybersecurity researchers monitoring the dark web listing.
What Was Compromised
The leaked data reportedly includes Aadhaar numbers, savings and current account records, loan documentation, NetBanking user details, and internal branch audit records. The breach was contained after the bank identified unauthorized access and implemented immediate containment measures.
"The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data," the bank said in an official statement. "The matter was promptly identified, and immediate containment measures were implemented. The Bank's core banking systems were not accessed and continue to remain secure."
The bank has launched a forensic investigation in coordination with authorities.
A Recurring Problem
This incident marks the second significant data exposure for Bank of Baroda in less than a year. In September 2025, security firm UpGuard discovered a third-party cloud database misconfiguration that exposed approximately 6,000 customer records.
The current breach underscores a persistent vulnerability in banking infrastructure: employee email accounts remain a critical entry point for large-scale data exfiltration, even when core banking backends are hardened against direct attack.
Industry Reaction
Srikanth Lakshmanan, founder of CashlessConsumer, described the incident as "a cyber disaster." The leak exposes millions of customers to potential identity theft and targeted phishing attacks, given the sensitivity of Aadhaar numbers and financial account details included in the dumped data.
Some cybersecurity researchers have suggested possible links to the hacking group TripleX, which was previously connected to a breach of Indonesia's PT Bank Negara Indonesia. However, this attribution has not been independently confirmed by law enforcement or the bank.
Broader Implications
The breach arrives amid heightened cybersecurity concerns across India's financial sector. Banks have increasingly invested in securing core transaction systems, but this incident highlights how peripheral access points—such as employee email—can undermine those defenses.
The fact that the data was leaked for free, rather than sold, suggests the threat actor may be motivated by reputational damage rather than direct financial gain. Security experts warn that affected customers should remain vigilant for phishing attempts and monitor their accounts for suspicious activity.
Bank of Baroda serves over 100 million customers globally, with operations across 10 countries. The bank has not yet disclosed how many customers were affected by this specific incident.