Overview
- Cybersecurity monitors first flagged a large data listing on the dark web that was publicly noticed on Saturday and then shared by researchers, who say the archive was advertised at roughly 700GB to 1TB.
- Bank of Baroda says the incident resulted from unauthorized access to a single employee's email account and that its core banking systems were not accessed.
- Researchers who reviewed sample files report the leak contains customer records, scanned identity documents such as Aadhaar, loan and KYC forms, and internal audit and vigilance documents from multiple branches.
- Security analysts have pointed to the relatively new group TripleX based on similarities to past attacks, but no definitive claim or formal attribution has been confirmed by authorities.
- Customers are being advised to enable transaction alerts, change passwords, turn on two‑factor authentication and monitor accounts while the bank completes a forensic audit and regulators assess next steps.