Ahmedabad

Bank of Baroda's Shaken by Massive 1TB Data Leak: Customers’ Account Details and ID Files Dumped Online

By GS Team
27 Jul 20263 mins read
TukuTouch Logo
Bank of Baroda, a major Indian state-owned bank, suffered a catastrophic 1TB data breach, with sensitive customer and corporate records dumped on the dark web for free. The leak includes account details, Aadhaar records, and internal audit files, significantly impacting Gujarat. Suspected to be the work of cybercrime group 'TripleX,' the breach exposes millions to fraud. Bank launches probe, while customers are urged to monitor accounts and secure credentials.

Summarized by AI; it may make mistakes. Check important info

Bank of Baroda's Shaken by Massive 1TB Data Leak: Customers’ Account Details and ID Files Dumped Online
AI-image

In what cybersecurity experts are calling a monumental digital disaster, state-owned banking major Bank of Baroda, an institution deeply woven into the financial fabric of Gujarat has been hit by a catastrophic data breach, with over one terabyte (1TB) of sensitive personal and corporate records dumped on the dark web for free.

The massive leak, which first surfaced over the weekend, contains confidential records spanning branches across Gujarat and the rest of the country. The exposed files include names, contact details, savings and current account information, loan appraisal documents, and government-issued identification files such as Aadhaar records.

Internal Audits and Confidential Branch Files Exposed

The breach hits particularly close to home for Gujarat, where the Vadodara-headquartered lender serves millions of individual account holders, small businesses, and agricultural borrowers. The compromised repository goes far beyond basic contact details, revealing a vast array of the bank's internal operational records.

Among the leaked documents are branch audit reports, internal communications, vigilance investigation files, customer application forms, and security data linked to the bank's popular mobile platform, bobWorld.

The cyber attack was first flagged on Saturday, 25 July, by dark web tracking platform ransomware.live. Independent cybersecurity researchers who inspected the leaked sample sets confirmed the authenticity of several internal documents.

Srikanth Lakshmanan, a software engineer and founder of digital payments watchdog CashlessConsumer, underscored the magnitude of the fallout after reviewing the published samples.

"It's a cyber disaster," Lakshmanan noted, confirming that the published dataset contains a volatile mix of critical banking infrastructure documents alongside personal customer files.

Infamous Cybercriminal Outfit 'TripleX' Suspected

While no hacker group has officially claimed responsibility, threat intelligence analysts suspect a relatively new cybercrime collective operating under the name TripleX.

The group made international headlines in May 2026 after breaching PT Bank Negara Indonesia one of Indonesia's largest state-owned banks where they exfiltrated 2TB of data, including customer identities, contracts, and financial transaction histories, before dumping them on Tor-network hosting sites.

Unlike standard ransomware groups that demand heavy ransom payments to suppress data leaks, the threat actor in this instance uploaded the entire 1TB Bank of Baroda repository for public download without charging a fee, multiplying the exposure risk for millions of account holders.

Bank Launches Internal Probe as Account Holders Seek Answers

Sources familiar with the matter indicated that Bank of Baroda has launched an urgent internal investigation to determine how the breach occurred and verify the extent of the compromised data. However, the bank has not yet issued a formal public statement regarding the incident.

Regulators, including the Reserve Bank of India (RBI) and the Indian Computer Emergency Response Team (CERT-In), are monitoring developments, with official advisories expected following initial assessments.

The timing of the breach is particularly concerning for Gujarat's vibrant trade and retail ecosystem, where Bank of Baroda remains one of the primary financial backbones for small businesses, traders, and everyday depositors.

As the investigation continues, financial safety experts strongly advise all Bank of Baroda account holders to monitor their bank statements closely, change NetBanking credentials, and stay alert to fraudulent calls, phishing emails, or suspicious requests attempting to exploit the leaked information.