Bank of Baroda Investigates Alleged 1TB Data Leak Following TripleX Dark Web Claim


Bank of Baroda is investigating claims of a major cybersecurity incident after the ransomware group TripleX allegedly published a post on a dark web leak site claiming to possess around 1TB of data related to the Indian banking giant. In the post, the threat actor identified the target as "Bank of Baroda biggest Indian bank", listing the organization as a Banking & Financial Services institution located in Vadodara, Gujarat, India.
According to the threat actor, the allegedly leaked dataset contains a wide range of customer and internal banking information, including savings and current account records, NetBanking (bob World) data, personal and corporate banking records, NRI banking information, loan documents, customer support records, branch and ATM-related data, Aadhaar details, account information, and internal operational documents. Screenshots shared online also appear to show internal audit reports, inspection files, customer application forms, and directory listings containing confidential banking documents from multiple branches.




The alleged leak was reportedly published on a dark web portal with sample documents made publicly available. Security researchers who reviewed portions of the shared data indicated that the samples appear to include genuine-looking internal documents, although the complete dataset has not been independently verified. The threat actor behind the leak is believed to be TripleX, a cybercriminal group previously linked to attacks targeting financial institutions in Southeast Asia.
At the time of publication, Bank of Baroda has not officially confirmed that its internal systems were compromised, and the authenticity, source, and full extent of the alleged leak remain under investigation. There has also been no official confirmation from CERT-In or the Reserve Bank of India (RBI) regarding the reported incident.


If verified, this could become one of the largest publicly claimed data exposures involving an Indian banking institution. The incident highlights the growing cybersecurity risks facing the banking sector and reinforces the need for strong data protection, continuous threat monitoring, and proactive security measures to safeguard sensitive customer information.
Recommended Precautions
Monitor your bank account for suspicious transactions.
Enable SMS and email transaction alerts.
Never share OTPs, passwords, or banking credentials.
Beware of phishing emails, SMS messages, or phone calls using leaked personal information.
Contact your bank immediately if you notice any unauthorized activity.


NPAV Endpoint Security, Detects advanced threats and protects banking endpoints from cyberattacks.
NPAV Data Loss Prevention (DLP) – Helps organizations monitor, classify, and protect sensitive customer data while preventing unauthorized data leakage.