Physical Address
Bangalore, Karnataka, India
Physical Address
Bangalore, Karnataka, India

Indian state-owned lender Bank of Baroda has confirmed a data breach after an unauthorised party compromised an employee email account and accessed certain information available through it.
The bank said the incident did not affect its core banking systems, adding that containment measures have been implemented and a forensic investigation is underway to determine the scope of the exposure.
The disclosure followed the appearance of a large collection of files allegedly belonging to Bank of Baroda on a dark-web leak site.
Cybersecurity researcher Srikanth L, founder of Cashless Consumer, told that the exposed material included customer details, identification documents, loan files and internal audit records. Metadata associated with the leak indicated that the archive contained more than 700 GB of data.
Bank of Baroda has not confirmed the reported data volume or disclosed the number of customers affected.
It has also not revealed how the employee account was compromised, when the breach began or how long the attacker retained access.
The breach appears to have been limited to data accessible through the compromised employee identity, rather than the bank’s main transaction-processing environment.
However, the incident highlights how an email account can become a valuable target when it contains sensitive attachments or provides access to connected enterprise applications and document repositories.
Enterprise email identities are commonly linked to cloud storage, shared mailboxes and internal collaboration platforms. Compromising one account can therefore expose more than the messages stored inside the mailbox.
Bank of Baroda has not said whether the stolen information was stored directly in the employee’s email account or accessed through another service connected to it.
No malware, software vulnerability or phishing campaign has been publicly linked to the incident.
The bank has also not identified the attacker or described the breach as a ransomware attack.
The material examined by the researcher reportedly included customer information, identity documents, loan papers and internal audit records.
Such information could provide threat actors with enough context to create targeted phishing or impersonation campaigns that appear more credible than generic banking scams.
For example, an attacker using legitimate customer or loan information may pose as a bank employee and claim that an account, KYC record or loan application requires urgent verification.
There is currently no evidence that such follow-on attacks have occurred in connection with the breach. But customers should remain cautious of unexpected communications that reference real personal or banking information.
Users should pay particular attention to:
Knowing a customer’s name, branch, loan details or identity information does not prove that a caller represents the bank.
Bank of Baroda said its core banking systems remain secure, indicating that the attackers did not gain access to the infrastructure responsible for maintaining account balances and processing financial transactions.
There is no public evidence that the attackers modified customer accounts, initiated transactions or disrupted the bank’s banking services.
The confirmed impact is currently limited to unauthorised access to data through the compromised employee account.
However, the full scale of the breach will depend on the amount and sensitivity of the information obtained and whether the leaked archive is authentic.
The forensic investigation is expected to establish how the account was compromised, what systems were accessible through it and how many customers or employees were affected.
Until those findings are released, the reported archive size and complete list of exposed records remain unverified.