Bank of Baroda Confirms Data Breach, Employee Email Compromised; Shares Down 1%

  • Updated: 28 Jul 2026, 4:22 PM IST
  • 4 Min. Read

Bank of Baroda Confirms Data Breach, Employee Email Compromised; Shares Down 1%

Bank of Baroda has confirmed a data breach after a threat actor claimed to have published over 1TB of the bank's data on the dark web, with the incident traced to a compromised employee email account. The bank says its core banking systems remain secure. Read ahead to know more.

Bank of Baroda has officially confirmed a security incident following claims that a large volume of its data had been exfiltrated and published on the dark web. The bank said a compromised employee email account gave attackers unauthorised access to certain data but maintained that its core banking systems were not accessed and remained secure.

A forensic investigation has been initiated, and the bank said it is working with relevant authorities in line with applicable regulatory requirements.

Bank of Baroda shares on 28 July 2026 at 03:30 pm were trading down 1.97% at ₹239.20.

The bank's statement confirmed the essential facts while stopping short of specifying the volume of data affected. It said the incident was promptly identified and immediate containment measures were put in place.

The bank added that it remains committed to maintaining high standards of information security and protecting customer trust.

The Bank of Baroda data breach came to public attention over the weekend of 25 July after posts on social media and dark web monitoring accounts flagged a large listing on a dark web forum. The threat actor, identified as the Triple X ransomware group, claimed to have exfiltrated approximately 1TB of Bank of Baroda data, with some accounts placing the figure at over 700GB.

The Bank of Baroda data leak reportedly covers a wide range of records, including customer KYC documents, savings and current account details, loan appraisal papers, internal audit data, vigilance handbooks and information linked to NetBanking users, NRI accounts and corporate banking services. The material is said to have come from the bank's internal SharePoint or file-sharing infrastructure rather than its core banking database.

Screenshots circulated by a software engineer on X showed account opening forms containing names, photographs and identification numbers, alongside copies of loan documents and audit files. The data reportedly spans approximately five years and encompasses over 92,000 files across nearly 9,800 directories.

According to the threat actor's own claims, the initial access vector was a weak password on an employee account. Attackers allegedly used compromised credentials to move through the bank's internal network before reaching the file server and exfiltrating the data over an extended period.

Bank of Baroda share price movement following the disclosure was being watched by investors, as the bank is India's second-largest public sector lender. The bank has not provided further details on the timeline or the specific systems affected beyond what was included in its official statement.

Also Read - Ambuja Cements Q1 FY 2026-27 Results

This article is for informational purposes only and should not be considered investment advice from Kotak Neo. For compliance T&C and disclaimers, visit www.kotakneo.com/disclaimer.

About the Author
Kotak News Desk
Kotak News Desk

Kotak News Desk brings you latest updates, expert insights, and market-ready ideas - helping you stay informed and invest smarter.

Connect on: Linkedin

Did you enjoy this article?

0 people liked this article.