Bank of Baroda Investigates Alleged 1TB Customer Data Leak on Dark Web
Bank of Baroda is investigating claims of a 1TB data breach posted on the dark web, allegedly containing sensitive customer information, including Aadhaar numbers, loan records and banking documents. Cybersecurity specialists raised the alarm.
There have been reports of a hack on Bank of Baroda. An anonymous hacker has purportedly leaked 1 terabyte of sensitive financial data onto the dark web. The hacker claims to have broken into the bank's systems. Aadhaar numbers, names, and loan information from various branches across India are all part of the data set that was hacked.
Also, the hacker has posted example documents that were compromised online. Srikanth Lakshmanan, a software developer and creator of CashlessConsumer, said on X that the link to the sample documents was live. Srikanth revealed the hack by saying, "It's a cyber disaster."
Root folder of the data dump of @bankofbaroda #Databreach by threat actor. More verification links in the thread. The link is live.
— Srikanth.CashlessConsumer | ஸ்ரீகாந்த் (@logic) July 26, 2026
This is SOS @Cyberdost @RBI
cc @latha_venkatesh @dugalira @nit_set @suchetadalal https://t.co/6HZ2c6V6S5 pic.twitter.com/tWFCKJWv8Q
Highly Sensitive Info Now Live on Dark Web: Lakshmanan
The credibility of the data breach is being investigated internally by Bank of Baroda. Bank of Baroda has remained silent regarding the claims up to this point. Not even the Reserve Bank of India or CERT-In has confirmed it. The hacker asserts that one terabyte of sensitive material was made public. Information pertaining to savings and checking accounts, loans, NRI and corporate banking services, customer assistance, records pertaining to branches or ATMs, and customer support materials are all part of this category.
Dark web tracking site ransomware. Live reportedly discovered the breach on July 25, according to Srikanth. Customer information and internal Bank of Baroda records are among the data sets that have been made public, according to Srikanth. Regardless, no hacker has come forward to claim credit for the incident. According to Srikanth, a new hacking collective known as Triplx X might be responsible for this assault. He elaborated by saying that the perpetrator, TripleX, who had past involvement with an Indonesian bank, had made the complete dataset accessible to the public via a tor site.
Growing Cybersecurity Threat in India’s Banking Sector
Apprehension about cyberattacks is on the rise, and this incident has hit the banking industry especially hard. Even India has asked its financial institutions to take precautions after AI models like Claude Mythos caused a global uproar. Although Bank of Baroda's internal systems have not been compromised as of late, cybersecurity company UpGuard revealed in September 2025 that over 2,73,000 Indian financial records were housed in an exposed cloud database.
Six thousand of those were associated with the Bank of Baroda. Although this system was a third party. The biggest state-owned bank in Indonesia, PT Bank Negara Indonesia, was breached in May of this year by TripleX. The thieving ring was able to get their hands on about 2 terabytes of data, which included internal banking documents, customer contracts, and financial transaction records.