State-owned Bank of Baroda (BoB) has confirmed a cybersecurity incident involving the compromise of an employee’s email account that resulted in unauthorised access to certain data.
In a statement posted on X, the bank said the incident was identified promptly and immediate containment measures were implemented. Bank of Baroda clarified that its core banking systems were not breached and continue to remain secure.
The bank said it has launched a forensic investigation into the incident and is working closely with the relevant authorities in line with regulatory requirements. “The Bank remains committed to maintaining the highest standards of information security and to safeguarding the trust of its customers and stakeholders,” it said.
The confirmation follows social media posts claiming that nearly 1 terabyte of Bank of Baroda data, including personal and corporate banking records, had been stolen and advertised on a dark web forum. However, the bank has not confirmed the volume or nature of the data allegedly accessed.
According to Reuters, citing cybersecurity researcher Srikanth L, the leaked dataset reportedly includes customer information, identity documents, loan-related records and internal audit files. The data is said to have appeared on a dark web marketplace over the weekend and was advertised as containing more than 700 GB of information.
The incident underscores the growing cybersecurity risks facing financial institutions, particularly as employee accounts continue to be targeted by threat actors seeking access to sensitive organisational data.



