A major cyber security concern has emerged surrounding Bank of Baroda, one of the country's prominent public sector lenders, following claims that a vast amount of customer data has been leaked online. According to reports citing dark web monitoring platform Ransomware.live, approximately 1 TB of data belonging to anywhere between 1 lakh and 3 lakh customers has been dumped on the internet. A newly emerged cyber criminal group going by the name TripleX is reportedly being linked to this incident. However, financial institutions and security watchdogs have not yet issued any official confirmation regarding the authenticity of these claims.
What the Alleged Data Contains
The listing in question reportedly appeared on the internet on July 24, suggesting that the compromised data includes account opening forms and associated paperwork for a substantial number of account holders. The claims specify that the leaked cache contains customer photographs, identity verification documents, and multiple sensitive records. Furthermore, details linked to Aadhaar cards, savings and current account histories, loan applications, net banking documents, alongside NRI banking and corporate banking records, are said to be part of the leak. If these assertions prove accurate, a large segment of the customer base could face severe privacy risks.
Expert Observations and Sample Files
CashlessConsumer founder and software engineer Srikanth Lakshmanan took to the social media platform X to share details regarding this alleged security breach. He stated that he reviewed several sample files purportedly shared by the hackers. These included internal bank reports, branch audits, loan appraisal papers, vigilance investigation documents, bob World audit reports, and customer application forms originating from branches across the country. He described the situation as a major cyber disaster.
Background of the Cyber Group
The group allegedly behind this breach, TripleX, has previously made headlines for similar activities. The same cyber criminal collective had earlier claimed responsibility for stealing roughly 2 TB of data from Bank Negara Indonesia, a prominent state-owned bank in Indonesia. Consequently, this latest assertion has heightened alertness among cyber security agencies monitoring threats against financial infrastructure.
Official Stance and Response
As of the time of writing, Bank of Baroda had not released any official statement addressing the alleged data leak. Similarly, the Reserve Bank of India and CERT-In have not verified the occurrence of this reported incident. Therefore, the matter remains classified as an unverified claim pending official scrutiny.



















