Customer data from India’s Bank of Baroda leaked online, source and researcher say

By The Straits Times | Created at 2026-07-27 10:56:42 | Updated at 2026-08-03 17:13:22 1 week ago

MUMBAI – Customer data from India’s state-run Bank of Baroda, along with internal documents, has been leaked on the dark web, according to a source familiar with the matter and a cybersecurity researcher.

The leaked data includes customer details, identification documents, loan papers and internal audit records, said cybersecurity researcher Srikanth L, founder of Cashless Consumer.

A source familiar with the matter confirmed the leak and said the bank was conducting a forensic audit.

It was not immediately clear how many customers were affected. Bank of Baroda has not notified stock exchanges of any breach.

Bank of Baroda, the Reserve Bank of India and India’s cybersecurity regulator CERT-In did not immediately respond to requests for comment.

The leak comes amid growing concerns over cybersecurity risks facing large companies and financial institutions that store vast amounts of customer and business data.

Preliminary indications suggest the incident stemmed from a compromised e-mail system, the source said.

The data appeared on a dark website on the night of July 25 and was advertised as a cache containing more than 700 gigabytes of information, based on metadata analysis of the site, Srikanth said.

In June, a cyberattack on Apple supplier Tata Electronics led to component design and specification documents linked to Apple and Tesla being leaked on the dark web.

Earlier in July, ransomware group World Leaks posted files on the dark web related to India’s largest nuclear plant. REUTERS

Read Entire Article