Bank of Baroda confirms data breach; cybersecurity experts see 1TB breach as ‘bad’ and ‘concerning’

/ 3 min read
AI Hub

BoB says core banking system secure, but experts say the bank might be vulnerable to more attacks from other hackers, stock edges down 0.91%.

THIS STORY FEATURES
The BoB data leak includes photos, accounts, mobile numbers, addresses, and signatures of individuals, home and gold loan data, insurance premium receipts, SIM details, and audit and inspection details.
The BoB data leak includes photos, accounts, mobile numbers, addresses, and signatures of individuals, home and gold loan data, insurance premium receipts, SIM details, and audit and inspection details.

State-owned lender Bank of Baroda (BoB) on Monday confirmed that a data breach involved "employee's email accounts, resulting in unauthorised access to certain data". The bank disclosed the incident in a post on X.

ADVERTISEMENT

"A comprehensive forensic investigation has been initiated and the Bank is working with the relevant authorities in accordance with applicable regulatory requirements," BoB said in a statement.

Cybersecurity experts call the data breach at Bank of Baroda—where a threat actor claimed to have leaked nearly 1TB of sensitive data on the Dark Web—as ‘concerning’ and ‘bad’ for the banking ecosystem.

ADVERTISEMENT

The data leak includes photos, accounts, mobile numbers, addresses, signatures of individuals, home and gold loan data, insurance premium receipts, SIM details, and audit & inspection details.

“The leak could now make Bank of Baroda more vulnerable to immediate attacks from other hackers, if they chose to attack,” said Ritesh Bhatia, founder of V4WEB Cybersecurity, who is a cybercrime investigator, incident response expert, and data privacy consultant.

Bank of Baroda said, “The matter was promptly identified and immediately containment measures were implemented, The Bank’s core banking systems were not accessed and continue to remain secure. The Bank remains committed to maintaining the highest standards of information security and to safeguard the trust of its customers and stakeholders,” the statement said.

Shares of the lender edged down 0.91% to ₹244.2 apiece on the BSE on Monday.

Recommended Stories

Cybersecurity researcher and CashlessConsumer founder Srikanth Lakshmanan also shared screenshots on X that he said showed the root folder of the alleged data dump. He stated that the download link was active and described the incident as "a cyber disaster".

To put the size of the alleged breach into perspective, 1 terabyte (TB) is equivalent to about 1,000 gigabytes (GB) and can store approximately 250,000 high-resolution photographs, 500 hours of HD video, or millions of pages of documents.

ADVERTISEMENT

“Cybersecurity attacks in the modern world are more psychological rather than just being technical,” Bhatia told Fortune India.

While both cybersecurity experts declined to comment on exactly how the data breach could have taken place, it is claimed that weak cybersecurity practices and weak passwords, could be the reason for the attack. “Even if a strong system is in place, hackers are persistent….once it has been decided to target an institution, they will target it,” Bhatia said.

Most Powerful Women In Business 2026
View Full List >

“This is bad, not what we expected from one of the top banks in the country,” said Yash Kadakia, founder of Security Brigade, a cyber security company. “Every corporate system is vulnerable, but to pull out 1TB of data is a big red flag. Most corporate security systems are well layered. Audits are done to try to prevent vulnerabilities, there is monitoring of unusual patterns and then prevention of data from going out. For this event to have happened, all of the layers should have failed,” Kadakia told Fortune India.

Normally both public and private sector lenders are very strict on cyber security. The RBI and the finance ministry has often publicly and privately pushed banks and NBFCs to pay the utmost attention and strengthen cyber security systems. And to be fair, cybersecurity at banks has improved dramatically.

In March, the Cyber Security and IT Risk Group (CSITEG) of the RBI released its advisory on best practices on customer data protection based on a thematic study on “Security of Consumer Data”. This focusses on a shift towards stronger governance, accountability, and continuous monitoring in the financial ecosystem.

NEXT STORY