Bank of Baroda has launched a forensic investigation after customer data and internal documents from the state-run lender surfaced on the dark web, the bank confirmed on 27 July 2026, Reuters reported.
The bank said the breach resulted in “unauthorised access to certain data” but that attackers did not access its core banking systems, which remain secure. It has implemented initial containment measures and is working with the relevant authorities, it added. A source told Reuters that preliminary indications point to a compromised email system, and that the bank is running a forensic audit.
The leaked cache spans both customer and internal bank records, cybersecurity researcher Srikanth L, founder of digital payments watchdog CashlessConsumer, said. According to him, the cache includes:
- Customer details, identification documents and account application forms from branches across India
- Loan appraisal and assessment documents
- Branch audit reports and BobWorld mobile-platform audit records
- Internal communications and vigilance investigation files
The dataset appeared on a dark web site on Saturday night and was advertised as containing more than 700 gigabytes of data, based on his metadata analysis.
What customers should do now: Srikanth has published a consumer advisory telling Bank of Baroda customers to assume attackers have exposed their personal data. He urges customers to:
- Enable transaction alerts on all accounts.
- Change NetBanking passwords and switch on two-factor authentication.
- Review recent transactions for unauthorised activity.
The advisory flags phishing calls, SIM-swap attacks and fraudulent loan applications misusing leaked Know Your Customer (KYC) records as the main follow-on risks. It directs customers to the RBI Banking Ombudsman and the national Cyber Crime portal, and references a Central Bureau of Investigation (CBI) First Information Report (FIR) it says authorities have filed.
A wider run of Indian data breaches: The leak deepens concern over how firms and financial institutions holding large customer datasets protect them. In June 2026, attackers hit Apple supplier Tata Electronics and leaked component design documents linked to Apple and Tesla on the dark web. Earlier in July, ransomware group World Leaks posted files on the Kudankulam nuclear plant, India’s largest.
Also read:
Source link
Disclaimer
We strive to uphold the highest ethical standards in all of our reporting and coverage. We blogs.grocliq.com want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.
Website Upgradation is going on for any glitch kindly connect at [email protected]