Bank of Baroda is investigating an alleged 1TB data leak stemming from a compromised employee email account. While the bank confirmed that its core banking systems remain fully secure, cybersecurity experts warn that the exposed records could expose customers to sophisticated phishing attempts.
State-owned Bank of Baroda launches a forensic investigation after an email compromise allegedly exposes nearly 1TB of internal and customer records.
As cybersecurity concerns mount across India’s financial sector, Bank of Baroda (BoB) has confirmed a security incident involving unauthorized access to data following a compromised employee email account. The development came to light over the weekend of July 25–27, 2026, after dark web monitoring platforms flagged that a threat actor had allegedly published an archive containing roughly 1 terabyte (1TB) of sensitive files. While independent cybersecurity researchers and digital rights advocates have warned that the leak includes customer application forms, loan details, and identity documents, the state-owned lender has strongly maintained that its core banking infrastructure remains entirely secure.
Forensic Probe and Official Disclosures
According to official statements and exchange filings released by Bank of Baroda, the unauthorized exposure stemmed from a business email compromise (BEC) rather than a direct breach of the bank’s main transaction servers.
Core Systems Unaffected: The Mumbai-based lender emphasized that its core banking systems (CBS) were not accessed during the incident and continue to function securely without disruption.
Independent Audit Engagement: BoB has engaged a CERT-In empanelled forensic auditing agency to examine the exact scope of the data exfiltration and implement remedial measures.
Contagion Containment: Immediate containment protocols were activated upon detecting the anomaly, with regulatory bodies being kept informed in line with statutory disclosure norms.
Scope of the Alleged Leak and Expert Warnings
Independent security researchers, including CashlessConsumer founder Srikanth Lakshmanan, analyzed preliminary samples and directory listings of the leaked files circulating on dark web forums. The files reportedly span branch audit reports, internal communications, loan appraisal papers, and customer account-opening forms containing identity records. While financial experts note that critical transaction credentials—such as ATM PINs, UPI passwords, and OTP mechanisms—are absent from the dump, the exposure of Personally Identifiable Information (PII) presents severe secondary risks. Fraudsters armed with names, contact data, loan figures, and identification numbers can potentially execute high-precision phishing attacks or social engineering scams targeting vulnerable retail customers.
Why It Matters
For millions of bank customers, a data leak of this magnitude underscores the growing threat of targeted cyber-frauds. Although direct monetary theft via core banking penetration has been averted, exposed personal data significantly elevates the risk of deceptive phone calls and phishing texts. Customers must remain extremely cautious regarding unsolicited communications requesting sensitive security credentials or verification codes.
Key Facts at a Glance
Incident Type: Potential business email compromise and data exposure.
Reported Volume: Approximately 1 terabyte (1TB) of data allegedly posted on dark web forums.
Core Systems Status: Unaffected and operating securely, according to bank officials.
Action Taken: Forensic audit launched through a CERT-In empanelled agency alongside containment protocols.
Frequently Asked Questions
Was Bank of Baroda's core banking system hacked?
No. Bank of Baroda has clarified that its core banking infrastructure was not accessed and remains completely secure, attributing the incident to an employee email compromise.
Are customer bank balances and funds at risk from this leak?
Security experts note that foundational credentials like passwords, UPI PINs, and OTPs were not part of the leak, meaning direct account drains are unlikely without active customer participation via phishing.
What kinds of documents are reportedly included in the leaked data?
Preliminary reports indicate the dataset contains internal audit logs, branch documents, loan papers, and customer application files.
Source: Bank of Baroda, CERT-In, Livemint, The Indian Express