One of India’s largest public sector banks is investigating a reported cybersecurity incident after customer information and internal documents allegedly surfaced on the dark web. Bank of Baroda confirmed that it has initiated a forensic investigation following the discovery of unauthorised access to certain data, while assuring customers that its core banking systems remain unaffected.
The incident comes as financial institutions across the world face growing cyber threats targeting sensitive customer records and internal corporate information. Although the full extent of the breach has yet to be determined, cybersecurity experts say the leaked dataset appears to be significant.
Bank of Baroda Confirms Security Investigation
In a statement issued on Monday, Bank of Baroda said it had already implemented initial containment measures and was working closely with relevant authorities to investigate the incident. According to the bank, the breach originated from a compromised employee email account, which allowed unauthorised access to certain information.
The lender stressed that the attack did not compromise its core banking infrastructure. The bank said, “The bank’s core banking systems were not accessed and continue to remain secure.” It also confirmed that a detailed forensic investigation is now underway to determine exactly what information was accessed and how the breach occurred.
At this stage, the bank has not disclosed how many customers may have been affected. Authorities are expected to assess the scope of the incident as the investigation progresses.
Researchers Say Customer and Internal Records Were Exposed
According to cybersecurity researcher Srikanth L, founder of Cashless Consumer, the leaked information reportedly includes customer details, identification documents, loan-related papers and internal audit records. Based on metadata analysis, the files were advertised on a dark web marketplace as containing more than 700 gigabytes of data.
The researcher said the information first appeared on the dark web over the weekend, raising concerns about the potential misuse of sensitive financial and personal information if the authenticity of the files is confirmed.
Reuters reported that it could not independently verify the leaked dataset or determine the total number of affected customers. India’s central bank, the Reserve Bank of India (RBI), and the country’s cybersecurity response agency, CERT-In, had not publicly commented on the matter at the time of reporting.
Cybersecurity Threats Continue to Target Major Organisations
The reported Bank of Baroda incident adds to a series of high-profile cybersecurity cases involving major organisations in recent months. As banks, technology companies and manufacturers continue storing vast amounts of digital information, cybercriminals have increasingly targeted employee accounts, cloud platforms and enterprise networks to gain access to valuable data.
In June, a cyberattack involving Apple supplier Tata Electronics reportedly resulted in confidential component design and specification documents linked to Apple and Tesla being leaked online. Earlier this month, ransomware group World Leaks also claimed responsibility for publishing files allegedly connected to India’s largest nuclear power plant, highlighting the growing sophistication of cyber threats targeting critical industries.
Security experts frequently warn that compromised employee credentials remain one of the most common entry points for attackers. Organisations are increasingly investing in stronger authentication systems, employee cybersecurity awareness programmes and continuous monitoring to reduce the risk of similar incidents.
For Bank of Baroda customers, the immediate focus will be on the findings of the ongoing forensic investigation. While the bank has emphasised that its core banking systems remain secure, the investigation is expected to determine what information was accessed, whether any customer records were exposed and whether additional protective measures are required in the coming weeks.
