Bank of Baroda Hacked, 1 TB of Data Available on Dark Web
Bank of Baroda has not responded publicly to the allegations, and there is currently no confirmation from CERT-In or the Reserve Bank of India (RBI) regarding the purported breach
Bank of Baroda has reportedly been hacked, and approximately 1 TB of its data is available on the dark web. The dataset contains both personal and corporate banking information across multiple branches in the country.
Sample documents shared by software engineer and founder of CashlessConsumer, Srikanth, on X, include Personally Identifiable Information (PII) of many customers.
Each of it contains account opening forms - with names, photo, UID etc pic.twitter.com/6kLMXFgROl
— Srikanth.CashlessConsumer | ஸ்ரீகாந்த் (@logic) July 26, 2026
"The site did contain a large number of folders/ files in what appeared to be the bank's internal file-sharing system. Multiple branch audit reports, audit reports related to bob World, customer data including loan application forms, including customer photos, Aadhaar numbers, and handwritten account opening forms were all accessible," he told The Left Shift.
Srikanth added that the attack appeared to be the work of a relatively new hacking group known as Triple X, which had previously targeted another bank in Indonesia.
It appears that the breach happened on July 24, 2026; however, the source of the data and the method by which it was allegedly obtained have not been disclosed.
Bank of Baroda has not responded publicly to the allegations, and there is currently no confirmation from CERT-In or the Reserve Bank of India (RBI) regarding the purported breach. The Left Shift reached out to Bank of Baroda for comment but had not received a response by the time of publication.
If authenticated, the incident could rank among the most significant cyber incidents involving an Indian financial institution in terms of the volume of data allegedly exposed.
However, cybersecurity experts caution that threat actors frequently exaggerate or fabricate claims to pressure victims or attract buyers, making independent verification essential before drawing conclusions.
The latest allegations come against the backdrop of previous security and compliance concerns at Bank of Baroda, although none involved a publicly confirmed large-scale cyberattack.
In October 2023, the Reserve Bank of India directed the lender to halt new customer onboarding through its bob World mobile app after supervisory concerns over irregular customer onboarding practices.
The issue stemmed from the misuse of customer accounts by banking agents rather than a hacking incident, prompting the bank to undertake corrective measures and a special audit.
More recently, in September 2025, cybersecurity firm UpGuard disclosed that an exposed cloud database containing more than 273,000 Indian banking records included over 6,000 entries linked to Bank of Baroda.
The database was traced to a third-party environment rather than the bank's infrastructure, and there was no evidence that Bank of Baroda's internal systems had been compromised. Nevertheless, the incident underscored the growing risks posed by third-party data exposure in India's banking ecosystem.
Financial institutions remain among the most targeted sectors as digital banking adoption accelerates. It is noteworthy that India ranks among the countries with the highest number of breached online accounts in recent years.
At the same time, major incidents involving Aadhaar-related data leaks have continued to surface through exposed cloud databases, compromised APIs, and dark web marketplaces.