Must read: ₹64 crore cyber scam unravels after teen behind AI-driven fake banking apps arrested by Surat police
Bank of Baroda data breach
To confirm the data breach, the hacker reportedly published sample documents. Srikanth Lakshmanan, software engineer and founder of CashlessConsumer, also shared sample documents on X and said the link to the leaked data was active.
Lakshmanan revealed that the alleged breach was first identified on July 25 by a dark web monitoring website called ransomware.live, and that data consists of both internal bank documents and customer information.
On the other hand, Other genuine Bank of Baroda-related documents consisted of branch audit reports, loan appraisal documents, internal communications including messages and documents, vigilance investigation records, and other customer data. However, Bank of Baroda, Reserve Bank of India (RBI), and CERT-In have not provided any comment or confirmation on the data breach.
Must read: NPCIL denies nuclear safety breach after reports of Kudankulam project drawings leak
As of now, no cybercriminal group has officially claimed responsibility for the alleged data breach. Lakshmanan believes that a new hacking group called “TripleX” could be behind the attack. The group was previously linked to an alleged attack on an Indonesian bank, where it breached over 2TB of data that included contracts, personal identification details, financial transaction histories, and internal banking documents.
Until regulatory bodies investigate the breach, it is advised that customers and partners should stay vigilant against unusual account activity, monitor credit reports, and follow standard cyber hygiene practices.
Bank of Baroda official statement on breach
Bank of Baroda has now issued an official statement acknowledging the cyber attack. The bank said, "The Bank has robust information security protocols in place. The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data."
"The matter was promptly identified, and immediate containment measures were implemented. The Bank's core banking systems were not accessed and continue to remain secure," the company said. The bank has also started an investigation with the concerned authorities to resolve the issue. "A comprehensive forensic investigation has been initiated, and the Bank is working closely with the relevant authorities in accordance with applicable regulatory requirements."