logo

India’s Bank of Baroda data breach exposes customer records after employee email compromise

Add The Asian Banker on Google
Discover more trusted banking and financial services insights by adding The Asian Banker as a preferred source on Google.
India’s Bank of Baroda data breach exposes customer records after employee email compromise
  • 259

A compromised employee email account allegedly exposed customer identification documents, loan records and internal audit files. The bank has not disclosed how much data was accessed or how many customers were affected.

Bank of Baroda has begun a forensic investigation after confirming that a compromised employee email account allowed unauthorised access to certain data.

The state-owned Indian lender confirmed the incident on 27 July. It said it had contained the breach and was working with the relevant authorities. Its core banking systems were not accessed and remain secure, according to the bank.

Bank of Baroda is India’s second-largest public sector bank after State Bank of India. Majority-owned by the Indian government, it reported global business of INR 30.51 trillion ($319 billion) at the end of June 2026 and operates more than 8,400 domestic branches.

A dark-web listing dated 24 July claimed that nearly 1 terabyte of Bank of Baroda data had been published. Independent digital-payments researcher Srikanth Lakshmanan later examined the material.

Customer and internal records allegedly exposed

Lakshmanan said the files included customer details, identification documents, loan papers and internal audit records. Indian media reports said samples also contained customer names, photographs, Aadhaar details, account-opening forms and account information.

The wider dataset was reported to contain records linked to savings and current accounts, net banking users, non-resident Indian customers, corporate banking services, branches and ATMs.

It remains unclear whether passwords, payment credentials, personal identification numbers or other authentication data were exposed, or whether fraudulent transactions have been linked to the incident.

Customer names, Aadhaar details, photographs and account information could be used for identity fraud or targeted phishing. The risk will depend on the authenticity of the files and the specific information exposed.

Bank of Baroda has also reportedly submitted a preliminary notification under a cyber-insurance programme led by National Insurance, the Economic Times said, citing people familiar with the matter. The programme reportedly provides total cover of INR 7.5 billion ($78 million), although the value of any claim has not been established.

Reporting deadlines apply from discovery

India’s Computer Emergency Response Team requires organisations to report specified cyber incidents within six hours of becoming aware of them.

Bank of Baroda is also covered by the Reserve Bank of India’s Cyber Security Framework for Banks. Its incident-reporting template gives banks two to six hours to submit an initial report to RBI.

India’s breach-notification regime will expand in May 2027, when the Digital Personal Data Protection Rules take effect. Companies will then have to inform affected individuals without delay and submit detailed information to the Data Protection Board within 72 hours.

Bank of Baroda has not disclosed when it became aware of the incident or when it notified the authorities.

The forensic investigation must establish the scale of the breach, identify affected customers and determine whether the exposed records have been used for fraud. Any regulatory action will depend on its findings and whether Bank of Baroda met the required reporting deadlines.

Chat with us WhatsApp