According to a post by the X handle DailyDarkWeb, the alleged leak includes Bank of Baroda's personal and corporate banking records.

State-owned lender Bank of Baroda is reportedly facing a major cybersecurity scare after a threat actor claimed to have leaked nearly 1TB of sensitive data on the Dark Web. While the bank has not confirmed the breach, the alleged leak has raised concerns due to its sheer scale, potentially exposing a vast trove of customer information, banking records, and internal documents.
To put the size of the alleged breach into perspective, 1 terabyte (TB) is equivalent to about 1,000 gigabytes (GB) and can store approximately 250,000 high-resolution photographs, 500 hours of HD video, or millions of pages of documents.
According to a post by the X handle DailyDarkWeb, the alleged leak includes Bank of Baroda's personal and corporate banking records.
The threat actor claims the dataset contains information related to savings and current accounts, loan records, NetBanking users, NRI and corporate banking services, customer support documents, as well as branch and ATM-related records. Sample files and download links have also reportedly been shared online.
"A threat actor has published samples and download links while claiming to possess approximately 1 TB of data associated with Bank of Baroda," the account said in a post.
However, the account noted that the claimed size and scope of the leak have not been independently verified and that the sample files alone do not confirm that the bank's core systems were compromised.
Cybersecurity researcher and CashlessConsumer founder Srikanth Lakshmanan also shared screenshots on X that he said showed the root folder of the alleged data dump. He stated that the download link was active and described the incident as "a cyber disaster."
Given the reported scale of the breach, Lakshmanan urged the National Payments Corporation of India (NPCI) and the Reserve Bank of India (RBI) to temporarily disconnect Bank of Baroda's systems from the network pending a forensic audit, arguing that the extent of the alleged compromise remains unknown and could pose broader risks to critical financial infrastructure.
"Given the scale of the breach, #CashlessConsumer strongly urges @NPCI_NPCI and @RBI to disconnect @bankofbaroda's systems from the network pending a forensic audit to safeguard critical infrastructure from contagion risk, given that the depth of the attack is unknown," he said in a post on X.
As of now, Bank of Baroda has not issued an official statement addressing the claims. There has also been no public confirmation from the Indian Computer Emergency Response Team (CERT-In), the RBI, or the NPCI regarding the authenticity of the alleged breach.
The source of the data and the method by which it was allegedly obtained also remain undisclosed.