Bank of Baroda Data Leak Exposes Customer Records and Internal Files on Dark Web

· · Views: 1,799 · 3 min time to read

Sensitive customer information and internal documents linked to India’s state-run Bank of Baroda have reportedly appeared on the dark web, prompting the lender to begin a forensic review while the scale and cause of the suspected breach remain under investigation.

A a person familiar with the matter confirmed that Bank of Baroda data had been exposed online and said the institution was conducting a forensic audit. The number of customers potentially affected was still unknown.

Customer IDs, Loan Records and Audit Files Reportedly Exposed

Cybersecurity researcher Srikanth L, founder of Cashless Consumer, shared that the exposed material included customer details, identity documents, loan papers and internal audit records.

The material allegedly contained Aadhaar numbers, customer names, savings and current account information, net-banking user details, and records connected to non-resident Indian and corporate banking services.

The files also reportedly covered customer-support materials, branch and ATM records, loan information from multiple locations, application forms, internal communications and vigilance investigations.

The Economic Times further listed branch audits, loan-appraisal documents and audit reports connected to the bank’s bob World digital platform among the allegedly exposed records. The publication said it could not independently verify the claims.

Reports Differ on Size of Leaked Database

The two reports offered different estimates of the data volume promoted online.

Based on his analysis of metadata from the dark-web site, Srikanth shared that the listing appeared on Saturday night and was advertised as containing more than 700 gigabytes of information.

The difference has not been publicly resolved, and neither report provided a verified total for the number of affected accounts or individuals.

Compromised Email System Examined as Possible Entry Point

Preliminary findings indicate that the incident may have originated from a compromised email system. The report did not identify the specific account or system allegedly compromised, nor did it explain how access may have spread to the wider collection of banking records.

No hacker or cybercriminal group had claimed responsibility for the reported breach as of its publication.

Bank of Baroda, the Reserve Bank of India and the Indian Computer Emergency Response Team, or CERT-In, did not immediately respond to requests for comment from Reuters.

India Faces Wider Wave of Dark-Web Disclosures

The suspected Bank of Baroda exposure follows other cyber incidents involving prominent Indian organizations.

Reuters reported that a June cyberattack against Apple supplier Tata Electronics resulted in design and specification documents associated with Apple and Tesla being posted on the dark web. Earlier in July, ransomware group World Leaks also published files reportedly connected to India’s largest nuclear power plant.

The Bank of Baroda case is particularly sensitive because the reported files combine identity information with banking, lending and internal operational records. Until the forensic audit establishes the scope and authenticity of the exposed material, the number of affected customers—and the risks they may face—remain uncertain.

Share
f 𝕏 in
Copied