India’s state-owned Bank of Baroda is investigating a data breach after customer information and internal documents were reportedly posted on a dark web site. The bank said the incident resulted from a compromised employee email account and emphasized that its core banking systems were not affected.
In a statement, the Mumbai-based lender said it had launched a forensic investigation after detecting the breach. It also implemented containment measures and is working with the relevant authorities while the investigation continues.
According to the bank, the attackers gained unauthorized access to certain data through the compromised email account. Bank of Baroda said its core banking infrastructure was not accessed and continues to operate securely.
The bank has not disclosed when the compromise occurred, how the employee account was breached, or how many customers may have been affected. It also has not confirmed the exact categories of information that were exposed.
Cybersecurity researcher Srikanth L, founder of Cashless Consumer, said the leaked files appear to contain customer records, identification documents, loan-related paperwork, and internal audit documents. According to the researcher, the data was advertised on a dark web leak site as a collection exceeding 700GB.
The reported size of the archive is based on the leak site’s metadata. However, the full contents of the dataset have not been independently verified, and Bank of Baroda has not confirmed the volume or nature of the leaked files.
At the time of publication, neither the Reserve Bank of India nor the Indian Computer Emergency Response Team (CERT-In) had publicly commented on the incident. The bank also has not announced whether affected customers will be notified individually.
Email account compromises can expose sensitive business documents and customer information stored in messages and attachments without directly affecting an organisation’s core operational systems. In this case, Bank of Baroda maintains that its banking platform and customer transactions were not impacted.
The incident follows several high-profile cybersecurity events involving major organisations in India. Financial institutions remain frequent targets because they store large volumes of sensitive customer information and confidential business records.
Bank of Baroda said its investigation is ongoing and that forensic experts are continuing to determine the scope of the unauthorized access. The bank maintains that its core banking systems remain secure while the investigation proceeds.