Concerns over Bank of Baroda’s cybersecurity have intensified after reports claimed that nearly 1TB of sensitive customer data linked to the public sector lender had surfaced on the dark web. The alleged breach has raised fresh questions about data protection in India’s banking sector, even as the bank insists that its core banking systems have not been compromised.
The alleged leak first came to light after a hacker claimed to be selling a massive database containing customer and internal banking information online. Cybersecurity researcher Srikanth L, founder of Cashless Consumer, said the leaked files appeared to include customer names, Aadhaar numbers, bank account details, phone numbers, loan records, internet banking information, corporate banking data, NRI banking records and internal documents. The hacker reportedly shared sample files to support the claim.
Responding to the reports, Bank of Baroda clarified that the incident was not a direct attack on its core banking infrastructure. Instead, the bank said the unauthorised access occurred after an employee’s email account was compromised.
In an official statement, the bank said it detected the incident quickly and immediately took steps to contain it. It stressed that customer transactions, deposits and digital banking services continue to function normally and that there has been no breach of its core banking platform.
The bank has also launched a detailed forensic investigation to determine exactly what data was accessed and how the incident occurred. It said it is working with cybersecurity experts and relevant authorities to assess the extent of the breach and ensure compliance with regulatory requirements.
At this stage, the bank has not confirmed whether the entire 1TB dataset being circulated online is authentic or whether all the information claimed by the hacker actually belongs to Bank of Baroda customers. Investigators are currently examining the leaked files to verify their contents.
While the bank has sought to reassure customers, the incident has once again highlighted the growing threat of cyberattacks targeting financial institutions. Cybersecurity experts say that even when hackers fail to penetrate a bank’s main systems, compromised employee accounts can still expose confidential documents and customer information if they are connected to sensitive internal networks.
The bigger concern now is not necessarily immediate financial losses but the possibility of identity theft, phishing attacks and financial fraud. If criminals gain access to personal details such as names, Aadhaar numbers, mobile numbers or account information, they can use the data to create convincing scams, impersonate bank officials or trick customers into revealing passwords, OTPs or UPI PINs.
Experts are urging Bank of Baroda customers to remain cautious over the coming weeks. Customers should avoid responding to unsolicited calls, emails or messages claiming to be from the bank. They should also never share confidential details such as OTPs, debit card PINs or internet banking passwords, regardless of how genuine the request may appear.
As a precaution, customers are advised to change their internet banking passwords, use strong and unique credentials, enable two-factor authentication wherever available and regularly monitor their bank accounts for any unusual transactions. Any suspicious activity should be reported to the bank immediately.
The incident has sparked widespread discussion on social media, with many users expressing concern over the scale of the reported leak. At the same time, cybersecurity professionals have cautioned against jumping to conclusions until the forensic investigation establishes whether all the leaked data is genuine and how much of it is actually linked to the bank.
The case also reflects a broader trend in cybercrime. Increasingly, hackers are targeting employees through phishing emails and stolen login credentials instead of attempting to break into heavily protected banking systems directly. A single compromised email account can sometimes provide access to sensitive business documents, making employee cybersecurity awareness just as important as technological safeguards.
For Bank of Baroda, the immediate focus is on completing the investigation, strengthening security measures and reassuring millions of customers that their money remains safe. While the alleged data breach has raised serious concerns about customer privacy, the bank maintains that its core banking systems remain secure and that normal banking operations continue without disruption.
The findings of the ongoing investigation are expected to provide greater clarity on the scale of the incident, the authenticity of the leaked data and whether any customer information has been misused. Until then, customers are being encouraged to stay vigilant and follow basic cybersecurity practices to protect themselves from possible online scams.