Summary of this article
Bank of Baroda faces alleged 1 TB data leak claims from sources.
Shared files allegedly include customer records, KYC documents and internal banking information.
No official confirmation yet; customers should remain alert against potential fraud risks.
Bank of Baroda (BoB) has been mentioned in claims of an alleged data leak after files and documents claimed to be linked to the bank were shared online, with a threat actor reportedly claiming access to around 1 TB of data. The claims were shared by Srikanth Lakshmanan, founder of CashlessConsumer, and dark web intelligence account DailyDarkWeb.
Details Of The Alleged Data Leak
Srikanth Lakshmanan shared posts on X claiming that he reviewed samples of the data shared online and that they appeared to contain Bank of Baroda-related information.
According to Lakshmanan, the alleged leak goes beyond KYC documents and includes customer-related records and internal banking documents. He shared screenshots of file directories and documents that he claimed included account opening forms containing names, photographs and identity details, along with loan appraisal documents, vigilance-related documents and internal audit records.
Lakshmanan also claimed that the shared files included a large number of internal documents and said the alleged attack date appeared to be around 24 June 2026, though he described it as a best-effort estimate and not a confirmed timeline.
He also flagged the matter with the Reserve Bank of India (RBI), Bank of Baroda and the Ministry of Electronics and Information Technology (MeitY).
Dark Web Intelligence Account Claims 1 TB Data Leak
Separately, DailyDarkWeb, a dark web intelligence account, reported in an X post that a threat actor had claimed to possess around 1 TB of Bank of Baroda-related data.
According to the account, the alleged dataset includes personal and corporate banking records, savings and current account information, NetBanking-related data, loan records, NRI and corporate banking services data, and customer support and branch or ATM-related information.
The account also shared details of alleged file directories that appeared to contain references to audit reports, branch documents, internal inspection records and other banking-related files.
Lakshmanan also pointed to a possible involvement of a group he identified as ‘Triple X’, describing it as a ransomware-as-a-service and data-extortion group first observed around May 2026. He said the group’s previously reported victims included Indonesia’s Bank Negara Indonesia (BNI).
Potential Risks For Customers
At the time of reporting, there has been no public confirmation from Bank of Baroda, the Reserve Bank of India (RBI), or any other official agency regarding the alleged data leak.
If the alleged data exposure is confirmed, customer information could potentially be misused for phishing, impersonation fraud and targeted scams. In his X posts, Srikanth Lakshmanan suggested precautionary steps for Bank of Baroda customers if the alleged data exposure is confirmed. He advised users to change digital banking passwords, enable transaction alerts, lock Aadhaar biometrics, monitor credit reports and stay alert against phishing and targeted scams.












