The record
Written from the 1 report below. Nothing here is unsourced.
- Bank of Baroda is investigating claims that around 1 TB of sensitive customer and internal banking data, including Aadhaar numbers and account details, was leaked on the dark web by a cybercrime group called TripleX.
- The bank said the incident involved the compromise of an employee's email account, not its core banking systems, and that containment measures were implemented promptly.
- Cybersecurity researcher Srikanth Lakshmanan, who verified sample files, questioned the bank's explanation, saying an email compromise alone could not lead to the exfiltration of such a large volume of data.
- The matter matters because it involves potentially exposed personal financial information of customers of one of India's largest state-owned banks.
What to watch next
- Whether Bank of Baroda publishes a detailed incident report as urged by the researcher
- Whether the bank alerts and supports potentially impacted customers
- Any further confirmation of the scale and contents of the leaked data on dark web monitoring platforms
Coverage1
1 report
English national1
All filed from India
Named India · Bank of Baroda · CashlessConsumer · Ransomware.Live · SOCRadar · Srikanth Lakshmanan · TripleX · X
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.