Bank of Baroda, one of India’s largest state run lenders, is facing allegations that hackers have leaked roughly 1TB of sensitive customer data on the dark web, according to Fortune India. A threat actor operating under the name Triple X claims to have stolen the data, which reportedly includes personal banking records, netbanking credentials, loan files and identity documents, according to a listing on the ransomware tracking site ransomware.live. As of this reporting, Bank of Baroda has not issued an official statement, according to Deccan Chronicle, leaving customers and regulators without confirmation of what, if anything, was actually taken.
What Data Was Allegedly Exposed?
According to Deccan Chronicle, the alleged leak includes Aadhaar details, loan account numbers and other personal information tied to Bank of Baroda customers. Srikanth Lakshmanan, a software engineer and founder of the consumer advocacy group CashlessConsumer, shared screenshots of sample documents on the platform X, according to the outlet, and said the download link for the alleged data dump was active at the time.
Separately, the ransomware.live listing describes a broader claim from the attackers: personal banking data covering savings and current accounts, netbanking credentials, and loan records spanning personal, home, car and education loans, along with NRI and corporate banking data. The listing states the attackers claim to hold what it describes as 100 to 300 thousand forms containing personal identification documents and photographs submitted by customers when opening accounts. None of these figures have been independently verified; they represent the attackers’ own claims rather than confirmed findings.
| What happened | Alleged 1TB leak of Bank of Baroda customer data reportedly offered on the dark web |
|---|---|
| Who claims responsibility | A threat actor group named Triple X, per a ransomware.live victim listing |
| Who is affected | Bank of Baroda retail, NRI and corporate banking customers, according to the listing |
| Data allegedly included | Aadhaar details, loan account numbers, netbanking credentials, ID documents and account forms |
| Bank’s response | No official statement issued as of this reporting, according to Deccan Chronicle |
Who Is Triple X and When Did the Claim Surface?
The ransomware.live listing names Triple X as the group behind the claim, with the listing surfacing on July 24, 2026, and an estimated attack date of May 12, 2026. That gap, if accurate, would mean the alleged intrusion sat undetected or unreported for more than two months before the data surfaced publicly, a pattern common among extortion groups that exfiltrate data quietly before going public to pressure a victim into paying.
The listing also cites infostealer intelligence from HudsonRock, reporting 892 compromised employee credentials, 247 compromised user credentials and 47 external attack surface exposures tied to the bank’s domain. Those figures describe credential exposure tracked separately from the alleged 1TB dump and have not been confirmed by Bank of Baroda.
Has Bank of Baroda Responded?
No. Deccan Chronicle reported that an official statement from Bank of Baroda was awaited at the time of publication, and Fortune India’s reporting likewise frames the breach as an allegation rather than a confirmed incident. Until the bank or India’s banking regulators weigh in, the scale, authenticity and freshness of the leaked data remain unverified. Attackers claiming a breach, and even posting sample documents, is not the same as an independently confirmed compromise, though the presence of a named victim listing on a ransomware tracking site is itself a signal worth taking seriously.
Why a Breach at a Public Sector Bank Raises the Stakes
Bank of Baroda operates at a scale that few Indian financial institutions match, with a footprint spanning retail, NRI and corporate banking. A confirmed compromise of Aadhaar numbers, loan documentation and netbanking credentials at that scale would sit alongside a run of 2026 incidents that have kept financial and personal data exposure in the headlines, including the Paidwork breach that exposed banking and personal data for 23 million users and the alleged theft of source code and cloud credentials from Accenture. It also echoes the pattern seen in the FortiBleed credential trove that exposed tens of thousands of Fortinet logins, where a large batch of sensitive credentials circulated on the dark web well before enterprises could confirm or contain the damage.
For Indian security leaders, the incident lands against a backdrop of rising personal liability. As outlined in our analysis of India’s evolving cybersecurity policy and CISO liability regime, regulators are increasingly expecting named executives, not just institutions, to answer for how customer data was protected and how quickly a breach was disclosed. A public sector bank sitting on an unconfirmed dark web listing for days without comment is exactly the scenario that new disclosure expectations are designed to close.
What Should CISOs and Security Leaders Do Now?
- Treat unconfirmed dark web listings as an active investigation trigger, not a wait and see item; engage threat intelligence vendors to validate sample data before making public statements.
- Audit exposed credential surfaces proactively. Infostealer telemetry like the figures cited in the ransomware.live listing often surfaces months before a full breach claim, giving defenders a head start if they are monitoring it.
- Prepare a disclosure playbook now. Silence during the window between an allegation and a confirmed breach erodes customer trust faster than a measured, even partial, acknowledgment.
- Revisit third party and vendor access tied to loan origination and NRI banking workflows, since bulk data claims of this kind often trace back to a single compromised application or partner integration rather than a core banking system.
Banks operate on trust, and that trust depends heavily on how employees and customers behave around credentials and phishing attempts, not just on firewalls. Our guide on security awareness training versus human risk management lays out why institutions with this scale of exposure need to measure behavioral risk, not just patch systems, to close the gap attackers are exploiting. Security leaders assessing what an incident like this means for their own institution may also find our broader look at what CISOs need to know in 2026 useful for benchmarking response readiness.
Infosec Federation will update this story as Bank of Baroda, the Reserve Bank of India or independent researchers provide further verification.
Frequently asked questions
What happened in the alleged Bank of Baroda data breach?
A threat actor known as Triple X claims to have stolen approximately 1TB of Bank of Baroda customer data and listed the bank as a victim on a ransomware tracking site. The claimed data includes Aadhaar details, loan records and netbanking credentials. Bank of Baroda has not issued an official confirmation of the breach.
Has Bank of Baroda confirmed the breach?
No. As of this reporting, Bank of Baroda had not issued an official statement addressing the alleged 1TB data leak, according to Deccan Chronicle. Fortune India’s reporting also frames the incident as an unconfirmed allegation. The authenticity, scale and freshness of the claimed data remain unverified pending a response from the bank.
Who is Triple X, the group claiming the Bank of Baroda breach?
Triple X is the name used by the threat actor group that listed Bank of Baroda as a victim on the ransomware tracking site ransomware.live, claiming roughly 1TB of stolen customer data. The listing dates the claim to July 24, 2026, with an estimated attack date of May 12, 2026.

Leave a Reply