Bank of Baroda has opened a forensic investigation into a data breach that put nearly a terabyte of customer records on the dark web. The state-run lender says the leak traces to one compromised employee email account and that its core banking systems were never touched.
It is at least the fourth time in a decade that Aadhaar-linked records have surfaced this way, and no single entity involved in the earlier leaks has faced public accountability for it.
A Compromised Inbox Exposes a Terabyte of Bank Data
Bank of Baroda confirmed the breach in a statement issued the evening of July 27, a day after word of the leak spread through social media posts. “A comprehensive forensic investigation has been initiated, and the bank is working closely with the relevant authorities in accordance with applicable regulatory requirements,” the bank said.
Cybersecurity researchers monitoring dark web and ransomware forums first flagged the files on July 25, two days before that statement. By then, screenshots and sample files were already circulating online, with posts claiming that more than a terabyte of bank data, including Aadhaar numbers, had been posted for free.
The bank has pointed to a single point of failure. “The incident involved compromise of an employee’s email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented,” it said, adding through a post on its official X handle that core banking systems “continue to remain secure.”
Branch Audits, Loan Files and Aadhaar Numbers in the Haul
The leaked cache is not limited to basic contact details. Cybersecurity researchers who reviewed sample files say it includes customer names, Aadhaar numbers, savings and loan account details, NetBanking credentials, non-resident Indian (NRI) account records, corporate banking files, and internal documents such as branch audits, loan appraisal files and customer application forms pulled from multiple branches.
This is a cyber disaster.
Srikanth Lakshmanan, a software engineer who founded the digital payments advocacy group CashlessConsumer, said that after reviewing sample files and checking internal branch documents against the bank’s own formats. Researchers investigating the leak believe a relatively new hacking group called TripleX may be responsible, pointing to its suspected earlier attack on a bank in Indonesia. Neither government agencies nor Bank of Baroda have confirmed the group’s involvement or the full scale of what was taken.
Bank of Baroda Joins a Decade of Aadhaar Leaks
The bank is the newest name on a list that goes back almost ten years. Aadhaar, India’s 12-digit biometric identity number issued by UIDAI (the Unique Identification Authority of India), has ended up exposed through banks, state agencies and government contractors even though UIDAI maintains its central database has never itself been hacked.
| Year | Incident | What Leaked | Outcome |
|---|---|---|---|
| 2017 (February) | Telangana state agency exposure | About 500,000 to 600,000 children’s Aadhaar records | Probe opened, no public penalty disclosed |
| 2017 to 2018 | An agent access scheme and a state utility leak | Names, addresses, phone numbers and photos tied to nearly 1.1 billion Aadhaar numbers | UIDAI said its central database was not breached |
| 2022 (April) | CAG audit of UIDAI vendors | Systemic vendor security gaps, not one dataset | Vendor oversight flagged, no fines made public |
| 2023 | Indian Council of Medical Research (ICMR) database hack | Aadhaar and passport data of 815 million people, offered for $80,000 | Government investigation opened |
| 2026 (July) | Bank of Baroda employee email compromise | Close to a terabyte of records including Aadhaar numbers and loan files | Forensic investigation ongoing |
UIDAI has published its own investigation into an earlier Aadhaar details leak case, one of several such reviews since 2017. Cybersecurity researchers cataloguing the pattern have tracked the 2017 to 2018 exposure’s scale as one of the largest identity data leaks anywhere.
A National ID That Cannot Be Reissued
A leaked debit card number gets cancelled within minutes, but there is no equivalent process for a 12-digit Aadhaar number once it leaks, because UIDAI designed it to follow a person permanently, tied to fingerprints and iris scans rather than a string that can simply be swapped.
- No reissue – there is no process to retire and replace the number; it is meant to last a lifetime.
- One number, many doors – the same digits serve as KYC for bank accounts, mobile SIMs, insurance policies and welfare schemes, so one leak can expose several unrelated accounts at once.
- Biometric anchor – Aadhaar ties the number to fingerprints and iris scans, credentials nobody can rotate the way they would a password.
The gap shows up in how banks are regulated, too. Reserve Bank of India rules require commercial banks to report a cyber incident within two to six hours of detecting it and to submit to annual audits by CERT-In (the Indian Computer Emergency Response Team) empanelled auditors. Those rules govern how fast a bank must notify its regulator, leaving the fate of an already leaked Aadhaar number outside their scope.
The vendor gap is not new either. A 2022 audit by India’s Comptroller and Auditor General (CAG) found that UIDAI had not effectively regulated the outside vendors holding its data, a finding a privacy watchdog’s review of the identity program’s recurring lapses had raised in similar terms years earlier.
Shares Slide as Weak Earnings Meet a Cyber Scare
Bank of Baroda shares slipped on the National Stock Exchange on Tuesday, trading around Rs 240.35, down roughly 1.5% from the previous close. The stock has been under pressure since the bank reported a soft set of June-quarter results that included a one-time charge of Rs 5,700 crore, or roughly $680 million.
The breach adds a fresh worry on top of that earnings miss. Bank of Baroda’s slide lands in a year when HDFC, Axis and Kotak have already trailed global bank stocks despite India’s boom, leaving little cushion for a sentiment shock like this one.
How Many Customers Are Affected?
Bank of Baroda has not disclosed how many customers had data exposed, and no regulator has published a figure either. The bank’s statements confirm only that one employee’s email account was compromised and that a forensic investigation is underway to determine the scope, a process that has taken weeks in comparable breaches elsewhere.
What We Know
- Compromised inbox – Bank of Baroda says one employee’s email account was accessed without authorization.
- Core systems intact – the bank says its core banking platform was not touched and remains secure.
- Scale claimed – researchers who reviewed sample files estimate close to a terabyte of records, including Aadhaar numbers, loan files and internal branch documents.
What’s Unconfirmed
- Customer count – neither the bank nor any regulator has said how many customers’ data was exposed.
- Government verification – CERT-In and the finance ministry have not publicly confirmed the leak’s scope.
- Attacker identity – the group known as TripleX is suspected but not officially named as responsible.
Early estimates from researchers who reviewed the leaked sample files suggest millions of Aadhaar numbers now sit exposed on the same forums, though that figure has not been independently verified by the bank or by CERT-In.
UIDAI has repeated its position that the central Aadhaar database itself has never been breached after every downstream leak since 2017, including the 2023 breach of 815 million records at India’s medical research council. Bank of Baroda’s forensic report has not been made public.
Frequently Asked Questions
Can Bank of Baroda Customers Get a New Aadhaar Number After This Leak?
No. UIDAI does not reissue a fresh 12-digit Aadhaar number after a breach, since the number is designed to stay with a person for life. Customers can lock their biometrics through the mAadhaar app or the UIDAI portal, and banks typically recommend changing NetBanking passwords and MPINs immediately after a leak like this one.
What Does CERT-In Do in a Bank Breach Investigation?
CERT-In empanelled auditors typically handle the technical root cause work in a bank breach, tracing how an attacker got in and how far they moved. That forensic report usually stays internal to the bank and its regulator rather than being published, unlike breach disclosures required in some other countries.
Has Bank of Baroda Said Anything About Compensating Affected Customers?
Not yet. Neither the bank’s July 27 statement nor its posts on X mention compensation, credit monitoring or a timeline for notifying individual customers. Bank of Baroda has said only that containment measures are in place and that the forensic investigation continues.
HDFC Bank Fines CEO Jagdishan Weeks Before Reappointment Call
Zepto’s IPO Valuation Target Sinks to $3 Billion From $7 Billion
Man Jailed Under a Rare Lifelong Order for Edinburgh Rape
Tata Power’s ₹6,675 Crore Bet on Solar Self-Reliance in Odisha
South Korea and Japan Chip Stocks Crash as China Surges
Scotland’s Social Work Registration Overhaul Carries a Staffing Cost