State-owned Bank of Baroda (BoB) on Monday confirmed a security incident that led to unauthorised access to “certain data” by threat actors. The incident involved comprise of an employee’s email account, BoB said.
“The matter was promptly identified and immediate containment measures were implemented,” BoB wrote in a post on X. While the bank did not elaborate on the scale of the data breach and what type of data was accessed by the threat actor, it said that core banking systems were not breached in the incident and continue to remain secure.
BoB further said that it is carrying out a forensic probe of the security incident. It is also working closely with relevant authorities in accordance with regulatory requirements. “The bank remains committed to maintaining the highest standards of information security and to safeguarding the trust of its customers and stakeholders,” the official statement read.
The bank’s confirmation comes after posts on social media alleged that nearly 1 terabyte (TB) of data, including BoB’s personal and corporate banking records, were stolen by a threat actor. The threat actor posted samples and download links of the allegedly stolen data on a dark web forum, according to Dark Web Intelligence, a handle on X that monitors hacker activity on such hidden data marketplaces. The 1 TB figure and the claimed scope of the data breach have not been independently verified, it added.
Based on metadata analysis of a dark web site, cybersecurity researcher Srikanth L, who also runs a consumer awareness initiative called Cashless Consumer, said the leaked data includes customer details, identification documents, loan papers, and internal audit records. The data appeared on a dark web site on Saturday night, July 25, and was advertised as a cache containing more than 700 gigabytes (GB) of information, Srikanth was cited as saying by Reuters.
However, the source of the leaked data and the method by which it was allegedly obtained by the threat actor remain undisclosed.
In a separate post on X, Srikanth urged Indian financial authorities such as the Reserve Bank of India (RBI) and the National Payments Corporation of India (NPCI) to disconnect BoB’s systems from the UPI network pending a forensic audit. Given that the depth of the attack is unknown, it is critical to safeguard critical infrastructure from contagion risk, he said.
The data breach comes amid growing concerns over cybersecurity risks facing large companies and financial institutions that store vast amounts of customer and business data.