Bank of Baroda Faces Alleged 1TB Customer and Corporate Data Leak

Bank of Baroda is facing an alleged cybersecurity breach after a threat actor claimed to leak approximately 1TB of sensitive customer and corporate data on the dark web. While the bank has not officially confirmed the incident, reported leaks include KYC documents and internal audit records.

The scale of the alleged leak is significant. A threat actor claims to possess nearly 1TB of data, which can store millions of pages of documents, approximately 250,000 high-resolution photographs, or roughly 500 hours of HD video. Though the bank has not yet issued a public statement, the claims have surfaced via X and dark web intelligence channels, raising alarms about the exposure of critical financial infrastructure.

The Contents of the 1TB Data Dump

The leaked dataset reportedly extends far beyond basic customer lists. According to reporting from Digit, the breach allegedly includes records for savings and current accounts, loan records, and details for NetBanking users. The scope also covers NRO and corporate banking services, branch records, and customer support details.

Sanjay Rawat
Photo: fortuneindia.com

The nature of the exposed files is particularly sensitive. Reporting indicates that sample screenshots show account opening forms, KYC documents, and loan appraisal notes. Even more concerning are the mentions of internal audit reports and vigilance handbooks, some of which contain photographs and account numbers.

  • Personal Data: Names, photos, and UID numbers.
  • Banking Records: Loan account numbers, customer statements, and corporate banking records.
  • Internal Documents: Branch and ATM-related records, internal audit data, and vigilance handbooks.

Srikanth Lakshmanan’s Warning of a Cyber Disaster

The breach gained public attention after Srikanth Lakshmanan, a software engineer and founder of CashlessConsumer, shared screenshots of the alleged root folder on X. He described the situation as a cyber disaster and noted that the download links for the data were live.

Over 4,600 RBFCU customers’ data may be leaked in data breach, Texas AG’s office says

Srikanth Lakshmanan, via Digit, stated that there is more sample data that goes beyond KYC documents, including vast amounts of internal audit data where each file contains account opening forms with names, photos, and UID numbers.

Lakshmanan tagged Bank of Baroda, the Reserve Bank of India (RBI), and the government’s cybersecurity awareness handle Cyberdost, urging authorities to investigate. He posted on X that the root folder of the Bank of Baroda data breach by a threat actor was available, noting that more verification links were in the thread, the link was live, and he was issuing an SOS to Cyberdost and the RBI.

1TB Bank of Baroda Data Allegedly Leaked on Dark Web
Photo: deccanchronicle.com

Because the depth of the attack remains unknown, Lakshmanan urged the National Payments Corporation of India (NPCI) and the Reserve Bank of India (RBI) to take drastic preventative measures. He argued that the bank’s systems should be disconnected from the network to prevent contagion risk to critical infrastructure until a full forensic audit is completed.

In a post on X, he stated that given the scale of the breach, CashlessConsumer strongly urges NPCI and RBI to disconnect Bank of Baroda’s systems from the network pending a forensic audit to safeguard critical infrastructure from contagion risk, as the depth of the attack is unknown.

Verification Gaps and Institutional Silence

Despite the evidence shared by researchers and the claims made by the X handle DailyDarkWeb, the breach remains unverified by official channels. Bank of Baroda has not confirmed or denied the incident. Furthermore, there has been no public confirmation from the RBI, the NPCI, or the Indian Computer Emergency Response Team (CERT-In).

The account DailyDarkWeb stated that a threat actor has published samples and download links while claiming to possess approximately 1 TB of data associated with Bank of Baroda. However, the account also noted that the claimed size and scope of the leak have not been independently verified and that the sample files alone do not confirm that the bank’s core systems were compromised.

Photo: ndtvprofit.com

Additional claims were shared by an X account called Dark Web Intelligence, which alleged that a threat actor shared sample files of the leak along with download links. This account claimed the leaked data includes both personal and corporate banking records.

The situation leaves several high-stakes questions unanswered: whether the data was stolen via a direct hit on the bank’s servers or through a third-party vendor, and how many millions of account holders are actually affected. Until the bank or a regulatory body provides a forensic timeline, the full risk to customers remains speculative but significant.

Related reading


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.