Last Update: 08/01/2026 at 1:00 PM EST

Bank of Baroda Data Exposure

Coverage from The Record, Security Boulevard, and others

Articles

9

Active Days

167

The Topic

Bank of Baroda Data Exposure topic image

Bank of Baroda acknowledged unauthorized access to certain data after an employee email account was compromised, while threat actors claimed to have obtained and published a much larger volume of customer and internal banking files. Reported material includes KYC documents, identity information, loan records, audit files and internal communications, but the bank has not confirmed the alleged volume, affected customer count or full authenticity of the archive. The incident highlights the exposure created by compromised credentials and file-sharing systems, as well as potential notification obligations under India’s Digital Personal Data Protection framework.

First Article: 02/13/26

Latest Article: 07/29/26

Summary

  • Bank of Baroda linked the incident to a compromised employee email account and said core banking systems were not accessed.
  • Threat actors and monitoring services alleged that up to roughly 1TB of data was taken from internal file-sharing or SharePoint infrastructure.
  • Reported samples include KYC forms, Aadhaar and PAN details, photographs, address proofs, loan documents, audit records and internal communications.
  • Triple X was identified in several reports as the alleged actor, while another report referenced the alias leak-king-F, leaving attribution unresolved.
  • The bank has not confirmed the alleged data volume, number of affected customers, geographic scope or whether customer data was exfiltrated.
  • Potential exposure of identity and financial documents could increase risks of targeted phishing, fraud, mule-account creation and unauthorized SIM acquisition.
  • India’s DPDP framework may require timely notification to regulators and affected individuals if a personal-data breach is established.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 167 Days

Feb 13Mar 13Apr 10May 22Jun 19Jul 17

Additional Articles

⭐⭐⭐⭐⭐

Kotak Neo07-28-2026
Bank of Baroda confirmed a ransomware-linked data breach in India after Triple X claimed dark-web publication of about 1TB of data, beginning to surface July 25, 2026.
Deccan Herald07-27-2026
Bank of Baroda reported an alleged 1TB customer-data exposure after employee email compromise enabled darknet leakage, with Triple X reportedly claiming responsibility.
DataBreachToday07-27-2026
Bank of Baroda disclosed a data exposure in India after employee email compromise and alleged ransomware posting by Triple X on July 24.
TechCrunch / Zack Whittaker02-13-2026
Odido confirms data breach affecting more than 6.2 million customers in the Netherlands, disclosed February 13, 2026.

⭐⭐⭐

Heroic07-13-2026
On July 13, 2026, a Telegram-uploaded stealer log exposed 6,358 SunCloudNew records with plaintext passwords, URLs, and API hosts.
The Federal07-27-2026
TripleX claims a nearly 1TB leak from Bank of Baroda in India, while Ransomware.live reports dark-web exposure and Bank of Baroda runs an internal investigation.