New Delhi: A threat actor has claimed to have hacked into Bank of Baroda (BoB) and put 1TB of sensitive data on the dark web for free.
The data allegedly includes personal and corporate banking details, be it Aadhaar numbers, names, and loans from multiple branches across India.
“The incident involved compromise of an employee’s email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The Bank’s core banking systems were not accessed and continue to remain secure,” BoB said in a statement.
It added that a “comprehensive forensic investigation” was underway with the bank working closely with the “relevant authorities in accordance with applicable regulatory requirements.”
Sample documents from the breach have been shared by the hacker online. Software engineer and founder of CashlessConsumer Srikanth Lakshmanan shared the sample documents on X, stating that the link was live.
When asked about the breach, Lakshmanan told India Today Tech: “It’s a cyber disaster.”
The bank is internally investigating the authenticity of the data leak, sources told India Today. The breach was first spotted on Saturday, July 25, by dark web tracking site ransomeware.live.
The data that has been put up online includes internal Bank of Baroda documents as well as customer details, Lakshmanan said.
“I was able to initially verify the documents and have found a range of internal documents of the bank,” he told India Today Tech.
“This includes branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country,” he said.
A relatively new hacking group called Triplx X may be behind this attack, Lakshmanan believes, though no hacker has publicly taken responsibility.
“The attacker – TripleX – which was previously involved in an Indonesian bank – has made the entire dataset publicly available on a tor site,” he said.
TripleX had breached one of Indonesia’s largest state-owned banks, PT Bank Negara Indonesia in May this year. The group managed to steal about 2TB of data, containing contracts, personal identification details, financial transaction histories, and internal banking documents.
This attack comes at a time when there is growing fear over cybersecurity threats, particularly in the banking sector. AI models like Claude Mythos had already rung alarm bells globally, with India also asking its financial institutions to implement proper safeguards.
In September 2025, cybersecurity firm UpGuard stated that an exposed cloud database contained more than 2,73,000 Indian banking records. 6,000 of which were linked to Bank of Baroda. This was a third-party system though.












