Bank of Baroda customers are being told to change their net banking passwords and debit card PINs after the state run lender confirmed on July 27, 2026 that a compromised employee email account led to unauthorized access to bank data, with a dark web listing dated July 24 claiming nearly 1TB of the material had been published, according to Business Standard. The bank says its core banking systems were not touched, but the exposure of personal and account linked records is enough on its own to fuel a wave of impersonation scams, according to Dynamite News.
| What happened | A compromised employee email account led to unauthorized access to Bank of Baroda data, with a dark web listing claiming close to 1TB was published, per Business Standard. |
|---|---|
| When | Bank of Baroda confirmed the incident on July 27, 2026; the dark web listing is dated July 24, 2026, per Business Standard. |
| Who is affected | Savings and current account holders, loan account holders, net banking users, NRIs and corporate banking customers, per Business Standard. |
| Scale | The listing, tracked on Ransomware.live, claims 100,000 to 300,000 customer application forms including photographs and identity documents, per Business Standard. |
| Regulatory angle | The Reserve Bank of India has directed the bank to investigate and warned of regulatory action, including possible liability under the Digital Personal Data Protection Act, 2023, if security lapses are confirmed, per Business Standard. |
| What customers should do | Change net banking and mobile banking passwords, update debit card PINs, and never share OTPs or passwords over calls, emails or messages, per Dynamite News. |
What data was exposed in the Bank of Baroda leak?
According to Business Standard, the alleged leak spans data tied to savings and current accounts, loan accounts, net banking users, non resident Indian (NRI) customers, corporate banking services, and branch and ATM records. Dynamite News reported that the categories separately cited include names, addresses, Aadhaar numbers, mobile numbers, and loan and banking paperwork. Both outlets note that passwords, debit card PINs and one time passwords (OTPs) have not been confirmed as part of the leaked material.
The listing was tracked on the dark web monitoring platform Ransomware.live, which Business Standard reported claims the dataset includes between 100,000 and 300,000 customer application forms, including photographs and identity documents submitted when accounts were opened. The incident adds to a run of large scale banking data exposures Infosec Federation has tracked this year, including an earlier report of a 1TB Bank of Baroda data breach surfacing on the dark web and a Paidwork breach that exposed banking and personal data for 23 million users.
Is Bank of Baroda’s core banking system actually compromised?
The bank says no. Business Standard reported that Bank of Baroda’s core banking infrastructure was not accessed and remains secure, meaning there is no evidence so far that attackers reached customer accounts or payment systems directly. The incident instead stemmed from a business email compromise, an employee account that gave attackers a foothold into internal data rather than the transaction systems themselves.
That distinction shapes how customers should weigh the risk. Business Standard’s reporting frames the more immediate danger as identity driven fraud, criminals using leaked personal details to build convincing phishing and impersonation attempts, rather than attackers moving money directly out of accounts.
How did the breach happen, and who is investigating?
Business Standard reported that Bank of Baroda has launched a comprehensive forensic investigation and is working with relevant authorities in line with applicable regulatory requirements. The Reserve Bank of India has directed the bank to investigate the alleged breach and warned of regulatory action if security lapses are found, according to Business Standard, which also reported that the RBI will examine whether Bank of Baroda met its cybersecurity and risk management obligations.
Business Standard reported that if the investigation finds the breach resulted from inadequate cybersecurity safeguards or failure to meet RBI incident reporting requirements, the bank could face regulatory penalties as well as liability under the Digital Personal Data Protection Act, 2023. Neither outlet has named the party responsible for the leak, and Infosec Federation is not speculating about attribution beyond what has been reported.
What should Bank of Baroda customers do right now?
Dynamite News outlined a short list of protective steps for account holders:
- Change net banking and mobile banking passwords immediately
- Update debit card PINs
- Never share OTPs, passwords or account details over calls, emails or messages, even if the sender claims to be calling from the bank
- Treat unsolicited calls referencing account or loan details as a potential scam rather than verified contact from the bank
As of July 28, 2026, neither outlet had reported confirmed cases of money being withdrawn from customer accounts, and Bank of Baroda had not published a full list of affected branches or customers, per Dynamite News.
Why does this leak matter beyond Bank of Baroda’s own customers?
Leaked Aadhaar numbers, addresses and account paperwork are precisely the raw material used to open fraudulent accounts and run social engineering scams at scale. Infosec Federation has previously reported on a Varanasi gang arrested for supplying mule bank accounts to cyber fraud rings and on how AI voice cloning and deepfakes are redefining financial fraud, both of which depend on exactly the kind of identity data now allegedly exposed from Bank of Baroda.
For security leaders, the RBI’s warning is the part worth sitting with. A bank’s ability to say, credibly and quickly, that core systems are untouched depends on segmentation, monitoring and email account hygiene decided long before an employee inbox is compromised, and on being able to prove it to a regulator. Infosec Federation examined that shift toward personal and institutional liability in its analysis of India’s 2026 cybersecurity policy and CISO liability, and the same accountability question is playing out globally, as covered in Infosec Federation’s look at US cybersecurity policy and executive liability.
Bank of Baroda customers will not know the full scope of the exposure until the forensic investigation concludes and the RBI completes its review. Until then, the safest assumption is that any unsolicited call, SMS or email referencing account details, however convincing, should be treated as a potential scam.
Frequently asked questions
What happened in the Bank of Baroda data leak?
Bank of Baroda confirmed on July 27, 2026 that a compromised employee email account led to unauthorized access to bank data, after a dark web listing dated July 24 claimed nearly 1TB had been published, according to Business Standard. The bank says its core banking systems were not affected and has launched a forensic investigation.
Is Bank of Baroda facing regulatory action over the leak?
The Reserve Bank of India has directed Bank of Baroda to investigate the alleged breach and warned of regulatory action if security lapses are confirmed, according to Business Standard. The bank could also face liability under India’s Digital Personal Data Protection Act, 2023, depending on the investigation’s findings.
What should Bank of Baroda customers do to protect themselves?
Dynamite News reported that customers should change their net banking and mobile banking passwords, update debit card PINs, and avoid sharing OTPs or account details over calls, emails or messages, even if the sender claims to represent the bank.

Leave a Reply