Bank of Baroda has confirmed a cybersecurity incident after threat actors claimed to have stolen and published sensitive bank data online. The bank said a compromised employee email account enabled unauthorized access to certain data, but added that its core banking systems were not accessed and that the incident was detected and contained quickly. Public reporting said leaked samples and directory listings appeared to include internal documents, customer onboarding records, audit materials, internal emails, loan documents, and corporate banking files, although the authenticity and full scope of the exposed data have not been independently verified.
Researchers tracking darknet activity said the stolen material was advertised for sale on underground forums and a Telegram channel by an actor identified in separate reports as "leak-king-F" and publicly linked elsewhere to Triple X. One report described the cache as roughly 1 TB of data spanning retail, corporate, and digital banking operations, while also noting an unverified claim that the breach stemmed from a weak password. Bank of Baroda had not confirmed customer-data exfiltration, and the incident raised concerns over fraud, phishing, and follow-on attacks if internal security and audit documents were exposed.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
In a filing with the Bombay Stock Exchange, Bank of Baroda said it had received a communication alleging unauthorized access to certain data. The bank said it launched an investigation with external cybersecurity experts and a CERT-In empanelled agency, and preliminary findings suggested a potential business email compromise.
Bank of Baroda said it has initiated a forensic investigation into the incident and is working with relevant authorities following claims that hundreds of gigabytes of bank data were leaked. The bank said the full scale of the alleged exposed dataset remains unverified.
In its response, Bank of Baroda said the incident was detected and contained immediately. The bank did not confirm whether customer data was exfiltrated and did not attribute the activity to a specific threat group.
Bank of Baroda disclosed that it experienced a cybersecurity incident after the leak claims surfaced. The bank said an employee email account was compromised, enabling unauthorized access to certain data, and stated that its core banking systems were not accessed or affected.
Researchers examining the exposed material said publicly accessible samples and directory listings appeared to include genuine internal files, customer onboarding records, audit materials, security documentation, internal emails, loan documents, and corporate banking records. However, the total scope and authenticity of all leaked data were not independently verified.
A threat actor publicly claimed to have stolen and published about 1 TB of alleged Bank of Baroda data, including internal documents and customer information. Public reporting linked the leak to the actor name Triple X in one account, while another report described an unidentified actor using the name "leak-king-F" to advertise the data on a darknet marketplace and Telegram.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourcethecybersecguru.com
Open sourcetimesofindia.indiatimes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.