Particle.news
Download on the App Store

Bank of Baroda Customer Data Appears on Dark Web After Employee Email Compromise

Regulators and the bank's forensic teams are investigating to confirm the scope, attribution and customer impact.

Overview

  • Cybersecurity monitors first flagged a large data listing on the dark web that was publicly noticed on Saturday and then shared by researchers, who say the archive was advertised at roughly 700GB to 1TB.
  • Bank of Baroda says the incident resulted from unauthorized access to a single employee's email account and that its core banking systems were not accessed.
  • Researchers who reviewed sample files report the leak contains customer records, scanned identity documents such as Aadhaar, loan and KYC forms, and internal audit and vigilance documents from multiple branches.
  • Security analysts have pointed to the relatively new group TripleX based on similarities to past attacks, but no definitive claim or formal attribution has been confirmed by authorities.
  • Customers are being advised to enable transaction alerts, change passwords, turn on two‑factor authentication and monitor accounts while the bank completes a forensic audit and regulators assess next steps.