Bank of Baroda is investigating claims of an alleged data leak after reports surfaced that nearly 1TB of customer and banking information was shared on the dark web. The leaked data is believed to include sensitive details such as Aadhaar information, loan records and internal banking documents. However, the bank has not confirmed any breach so far.
The issue came to light after an anonymous hacker allegedly claimed to have leaked a large amount of data linked to Bank of Baroda. The hacker claimed that the information was taken from the bank’s systems and included records from multiple branches across India.
The alleged dataset reportedly contains customer names, Aadhaar details, account information, loan records, NRI and corporate banking data, branch and ATM-related information, customer support records and internal banking documents.
The claims were first highlighted by Srikanth Lakshmanan, a software developer and founder of CashlessConsumer, who shared details about the alleged leak on X. He said that sample documents from the leaked dataset were accessible online and described the situation as “a cyber disaster.”
Bank of Baroda is currently verifying the authenticity of the claims and checking whether any customer information has been affected. The bank has not confirmed that its internal systems were compromised. The Reserve Bank of India (RBI) and CERT-In have also not issued any confirmation regarding the incident.
According to reports, dark web monitoring platform Ransomware.live identified the alleged leak on July 25. The platform reportedly found Bank of Baroda-related data, including customer information and internal records, being circulated online.
No hacker group has officially claimed responsibility for the alleged attack. However, cybersecurity observers have suggested that the TripleX group could be linked to the incident. The group was previously associated with an attack on Indonesia’s state-owned bank PT Bank Negara Indonesia, where around 2TB of data, including internal documents, customer contracts and financial records, was reportedly stolen.
The alleged leak has raised fresh concerns about cybersecurity risks in India’s banking sector. As digital banking services continue to expand, financial institutions are becoming increasingly attractive targets for cybercriminals due to the large amount of sensitive customer data they manage.
In a separate incident, cybersecurity firm UpGuard reported in September 2025 that an unsecured cloud server exposed around 2.73 lakh bank transfer records linked to multiple Indian financial institutions. Around 6,000 records were reportedly associated with Bank of Baroda. However, that incident involved a third-party system and was not a breach of the bank’s internal infrastructure.
Bank of Baroda’s investigation into the latest data leak claims is ongoing, and the authenticity of the leaked information is yet to be confirmed.
Read Article: India Allows FDI in Inventory-Based E-Commerce Model for Exports of Domestically Manufactured Goods

