Bank of Baroda (BoB), one of India’s largest state-owned lenders, has officially confirmed a cybersecurity incident after weeks of speculation over an alleged massive data leak circulating on dark web forums.
The bank issued a statement on X on Monday, July 27, 2026, acknowledging that an employee’s email account had been compromised, leading to unauthorized access to “certain data”.
In its official statement, BoB said it maintains “robust information security protocols” and that the incident stemmed specifically from a single compromised employee email account rather than a broader infrastructure failure.
Bank of Baroda Confirms Data Breach
The bank stated the intrusion was “promptly identified” and that “immediate containment measures were implemented” once the compromise was detected.
Critically, the lender emphasized that its core banking systems were not accessed and “continue to remain secure,” attempting to draw a clear boundary between the email-based breach and its transactional infrastructure.
The scale of claims driving public concern far exceeds what the bank has acknowledged. A dark web listing surfaced on the night of Saturday, July 25, advertising a cache of more than 700GB of data, with some social media posts and threat intelligence trackers claiming figures approaching 1TB.
According to PBS, citing cybersecurity researcher Srikanth L of Cashless Consumer, the leaked dataset reportedly includes customer details, identification documents, loan papers, and internal audit records.
Indian media reports further indicated the samples contained customer names, photographs, Aadhaar numbers, account-opening forms, and account information, with the broader dataset allegedly spanning savings and current accounts, net banking users, NRI customers, corporate banking clients, and branch/ATM data.
BoB has launched a comprehensive forensic investigation and stated it is “working closely with the relevant authorities in accordance with applicable regulatory requirements”.
A source familiar with the matter told Reuters that preliminary indications point to the breach originating from a compromised email system rather than core infrastructure.
The Times of India notes, citing people familiar with the situation, that BoB has also submitted a preliminary notice of loss under its cyber insurance program led by National Insurance, which provides total coverage of roughly INR 750 crore (approximately USD 78 million).
BoB has not confirmed the actual volume or authenticity of the leaked data, nor has it stated when it first became aware of the incident or when regulators were notified.
It also remains unclear whether passwords, payment credentials, PINs, or other authentication data were exposed, and whether any fraudulent transactions have been linked to the breach so far.
Notably, the bank has not filed any disclosure with stock exchanges regarding the incident, and both the Reserve Bank of India and CERT-In had not responded to requests for comment at the time of Reuters’ reporting.
Security researchers warn that exposure of Aadhaar numbers, photographs, and account details creates elevated risk of identity fraud and targeted phishing campaigns against BoB customers.
The incident again highlights email accounts as a persistent weak link in enterprise security, with one analysis noting the breach traces back to lax digital hygiene on a single employee credential.
As the forensic investigation progresses, further clarity is expected on the true scope of compromised records and the attacker’s initial access vector.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.