
New Delhi, A threat actor has claimed responsibility for an alleged cyberattack on Bank of Baroda, purportedly exposing more than 1TB of sensitive personal, financial and corporate banking data.
The reportedly compromised information includes customers’ names, Aadhaar numbers, bank-account details and loan-related records associated with multiple branches across India. The threat actor has allegedly made the dataset available for free on a dark-web forum.
Sample documents purportedly linked to the incident have also appeared online. However, the authenticity, scale and origin of the exposed records have not been independently established. It remains unclear whether the information was extracted directly from the bank’s core systems, a branch-level platform, a third-party service provider or another connected environment.
Bank of Baroda has not issued an official statement confirming the breach, the number of affected customers or the systems allegedly compromised. No public advisory confirming the incident has been issued by the Reserve Bank of India or the Indian Computer Emergency Response Team at the time of writing.
The presence of Aadhaar numbers alongside account and loan information could create risks beyond the initial exposure if the documents are authentic. Criminals may attempt to combine identity and financial information for phishing, social-engineering, impersonation and fraudulent loan or account-related communications.
Customers should remain alert to unsolicited calls, messages and emails requesting one-time passwords, card credentials, account passwords or remote access to their devices. Banks and government agencies do not ask customers to disclose such credentials through calls or messaging applications.
Determining the impact of the alleged incident will require a forensic investigation covering access logs, affected databases, third-party connections and the time during which unauthorised access may have occurred. Investigators would also need to examine whether the leaked files are current, previously exposed records or a combination of information collected from different sources.
If confirmed, the incident could become one of the most significant data exposures involving an Indian public-sector bank due to the reported volume and sensitivity of the information. Until an official investigation establishes the facts, claims concerning the size, source and authenticity of the dataset should be treated as unverified.
Bank of Baroda is one of India’s largest public-sector lenders, providing retail, corporate and international banking services through its branch network and digital platforms.




