Bank of Baroda is at the center of claims that 1TB of customer and internal data was posted on the dark web.

Bank of Baroda, one of India’s largest public sector banks, is at the center of an alleged cyber incident after a threat actor claimed to have accessed the bank’s systems and published 1TB of data on the dark web.
According to the claims, the leaked dataset contains a broad range of customer and corporate banking information, including Aadhaar numbers, customer names, savings and current account details, loan records, NetBanking user information, NRI and corporate banking service records, customer support files, and documents relating to bank branches and ATMs across India.
The alleged breach came to light after sample files began circulating online. Srikanth Lakshmanan, a software engineer and founder of CashlessConsumer, shared links to the files on X, saying they were publicly accessible. After reviewing the material, he described the incident as “a cyber disaster.”
Lakshmanan told India Today Tech that the alleged breach first appeared on the dark web monitoring website ransomeware.live. After examining the available files, he said he was able to verify that at least some of the documents appeared to be authentic.
“I was able to initially verify the documents and have found a range of internal documents of the bank,” Lakshmanan told India Today Tech.
According to Lakshmanan, the files include branch audit reports, loan appraisal documents, internal communications, vigilance investigation records, bobWorld audit reports, and customer application forms collected from multiple Bank of Baroda branches throughout India.
At the time of publication, no individual or hacking group had publicly claimed responsibility for the alleged breach. However, Lakshmanan said a relatively new threat group known as TripleX could be involved.
According to Lakshmanan, the same group was previously linked to an attack against PT Bank Negara Indonesia in May 2026, during which approximately 2TB of data was allegedly stolen. The exposed information reportedly included contracts, financial transaction histories, personal identification records, and confidential internal banking documents.
While Lakshmanan believes TripleX may be behind the Bank of Baroda incident, no independent evidence has confirmed the group’s involvement, and no threat actor has publicly taken responsibility for the alleged breach.
Bank of Baroda has not publicly confirmed that its systems were compromised or verified the authenticity of the alleged leaked data. As a result, the full scope of the incident remains unclear, including whether customer information was exposed or how the alleged attackers may have gained access.
Related articles :
- Hackers Threaten to Leak Data of 8M People After Odido Breach
- 108 Malicious Chrome Extensions Steal Data, Hijack Sessions
- Best Darknet Markets of 2026
Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.







