Menu

Bank of Baroda Breach Puts Millions of Aadhaar Numbers at Risk

A group tied to May’s breach of Indonesia’s BNI has allegedly dumped 1TB of Bank of Baroda data, including Aadhaar numbers, free on the dark web.

Ishan Crawford 4 hours ago 0 3

A threat actor claiming to have breached Bank of Baroda has dumped roughly 1TB of alleged customer and internal data on the dark web, free for anyone to download. The trove allegedly includes Aadhaar numbers, account records and loan files from branches across India. Bank of Baroda says the breach traces to one compromised employee email account and that core banking systems were never touched.

The same claimed actor, a group called TripleX, ran an almost identical operation against one of Indonesia’s largest state banks two months ago. That earlier case offers the clearest preview yet of where this one goes.

Was Only One Inbox Compromised?

Bank of Baroda says a single employee email account was compromised and that its core systems remain secure, while the leaked sample set reportedly spans branch audits, vigilance files and loan appraisals well beyond what one inbox typically holds. The bank has not yet reconciled that gap publicly.

In a statement posted on X, the bank said:

The incident involved compromise of an employee’s email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The Bank’s core banking systems were not accessed and continue to remain secure.

The bank added that a comprehensive forensic investigation was underway and that it was working with what it called relevant authorities in accordance with applicable regulatory requirements. It has not detailed how a single mailbox would have contained the range of internal material now circulating.

Branch Audits, Loan Files and Aadhaar Numbers Fill the Alleged Dump

Software engineer Srikanth Lakshmanan, founder of the digital payments consumer rights initiative CashlessConsumer, was among the first to review the leaked material and shared sample screenshots on X. Asked about the breach, he told India Today Tech it was “a cyber disaster.”

Lakshmanan said he checked the sample files himself. “I was able to initially verify the documents and have found a range of internal documents of the bank,” he said. He listed what he found: “branch audits, loan appraisal documents, internal communications, vigilance investigations, bobWorld audit reports, customer data including application forms across multiple BoB branches across the country.”

The claimed dataset, per that review, spans several categories:

  • Savings and current account records
  • Loan appraisal and disbursement data
  • NetBanking user details
  • NRI and corporate banking service records
  • Customer support and grievance material
  • Branch and ATM operational records

Lakshmanan said the leak was first flagged on Saturday, July 25, 2026, by dark web tracking site ransomware.live. Bank of Baroda has told India Today Tech it is running its own internal check on whether the full dataset is genuine. As of publication, the bank, the Reserve Bank of India and the Indian Computer Emergency Response Team have made no further public comment beyond the bank’s containment statement.

Indonesia’s BNI Saw This Playbook Two Months Ago

No hacker has formally claimed the Bank of Baroda breach under their own name. Lakshmanan pointed to TripleX, a hacking group he said had hit an Indonesian bank before this one. He said the attacker had made the entire dataset public on a Tor site, and identified TripleX as the group he believed was responsible.

TripleX’s earlier target was PT Bank Negara Indonesia, one of Indonesia’s largest state-owned lenders. That breach surfaced on May 22, 2026, and reportedly involved about 2TB of data spanning contracts, personal identification records and transaction histories dating back to 2024. TripleX listed the Indonesian bank’s data as free on the same dark web tracking database that later flagged the Bank of Baroda listing.

Lined up side by side, the two cases share a structure that goes beyond coincidence:

Detail Bank of Baroda (2026) Bank Negara Indonesia (2026)
First flagged July 25 May 22
Data volume claimed About 1TB About 2TB
Data types Aadhaar, accounts, loans, NetBanking, corporate and NRI records, internal audits Contracts, personal ID records, transaction histories, internal documents
Distribution Free download via Tor site Free download via Tor site
Alleged actor TripleX TripleX
Bank’s public position Confirms employee email compromise; says core systems secure Not addressed in the statements reviewed for this story

An Aadhaar Number Has No Reset Button

A stolen password can be changed in minutes. A stolen Aadhaar number cannot. Once the Unique Identification Authority of India issues a 12-digit Aadhaar number, it stays tied to that person for life; there is no mechanism to cancel or reissue it the way a bank swaps a compromised card.

That permanence is what makes a banking leak different from most consumer data spills. Account numbers can be closed. Loan files get updated every cycle. An Aadhaar number linked to a name, address and bank balance stays exploitable for as long as the person lives, regardless of what Bank of Baroda’s forensic report eventually concludes. UIDAI, the Aadhaar issuing authority, maintains that Aadhaar data is never breached at the source, a position that sits alongside a string of incidents involving Aadhaar numbers surfacing through banks, telecom systems and other linked services rather than UIDAI’s own database.

Bank of Baroda has been here before in a smaller way. In September 2025, cybersecurity firm UpGuard found an exposed cloud database holding more than 273,000 Indian banking records, of which about 6,000 were linked to Bank of Baroda. That exposure ran through a third-party system, not the bank’s own infrastructure, but it showed customer data tied to the bank reaching the open internet well before this larger, allegedly first-party incident.

A Six-Hour Reporting Clock Regulators Have Not Confirmed

Under CERT-In’s 2022 directions, banks and other regulated entities must report a qualifying cyber incident within six hours of becoming aware of it. The Reserve Bank of India’s own cybersecurity framework layers on further requirements: a 24/7 security operations desk and a board-approved cybersecurity policy for every bank it supervises. Non-compliance with the CERT-In timeline can draw penalties running to roughly one lakh rupees (around $1,200) a day, and Section 70B of the Information Technology Act allows for up to a year of imprisonment for failing to comply with directions.

Neither CERT-In nor the RBI has issued a public statement on the Bank of Baroda matter as of this writing, two days after the leak was first flagged.

  • What we know: Bank of Baroda has confirmed an employee email account was compromised, says core banking systems were not accessed, and has opened a forensic investigation with unnamed authorities.
  • What’s unconfirmed: Whether the full 1TB dataset is authentic, whether TripleX is genuinely responsible, and whether CERT-In or the RBI has been formally notified within the required window.

That silence does not necessarily mean the clock was missed. Regulators routinely receive incident reports without disclosing them publicly, since the six-hour rule governs notification to CERT-In, not disclosure to the public.

A Free Dump Spreads Faster Than a Ransom Note

Most extortion groups hold stolen data back and demand payment first, leaking only if a victim refuses to pay. TripleX skipped that step twice: in the Indonesian case and in the Bank of Baroda case, the data went straight onto a public Tor listing at no cost.

That choice changes who is exposed. A ransom demand gives a victim a window to negotiate, and keeps the buyer pool to whoever pays. A free dump puts the same files in front of every fraud operator, data broker and scam caller who finds the link, with no negotiation and no delay. For Bank of Baroda customers, that means the practical risk from this leak, if the data holds up as genuine, was already loose before the bank’s containment statement went out.

Bank of Baroda’s next public update will likely hinge on what its forensic investigation confirms and what, if anything, CERT-In or the RBI chooses to disclose. For now, the bank’s own account is a compromised inbox and a secure core; the dataset circulating online tells a broader story that has yet to be reconciled.

Frequently Asked Questions

What should Bank of Baroda customers do right now?

Customers can watch account and card statements for unfamiliar transactions, change NetBanking and bobWorld passwords as a precaution, and check their credit report for loan applications they did not make. Suspected fraud tied to the leak can be reported through India’s national cybercrime portal, cybercrime.gov.in, in addition to the bank’s own grievance channel.

Can a leaked Aadhaar number be changed or cancelled?

No. UIDAI does not deactivate or reissue Aadhaar numbers once assigned. The closest available safeguard is locking the biometric data linked to the number through the mAadhaar app or the UIDAI portal, which prevents the fingerprint and iris data from being used for authentication until unlocked.

Does CERT-In have to confirm the Bank of Baroda breach publicly?

Not necessarily. Banks must notify CERT-In of a qualifying incident within six hours of detection under the agency’s 2022 directions, but that reporting duty runs to the regulator, not to the public. CERT-In can direct a forensic audit and coordinate the response without ever issuing a public statement on a specific bank’s incident.

Written By

Prior to the position, Ishan was senior vice president, strategy & development for Cumbernauld-media Company since April 2013. He joined the Company in 2004 and has served in several corporate developments, business development and strategic planning roles for three chief executives. During that time, he helped transform the Company from a traditional U.S. media conglomerate into a global digital subscription service, unified by the journalism and brand of Cumbernauld-media.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *