


Customer data and internal documents from India's state-run Bank of Baroda have been leaked on the dark web, according to a source familiar with the matter and cybersecurity researcher Srikanth L, founder of Cashless Consumer. The leaked data reportedly includes customer details of identification documents, loan papers and internal audit records.
A source confirmed the leak and said the bank is now conducting a forensic audit. The number of customers affected remains unclear, and Bank of Baroda has not informed stock exchanges of any breach. The bank, the Reserve Bank of India, and India's cybersecurity regulator CERT-In did not immediately respond to requests for comment.
Preliminary findings suggest the breach originated from a compromised email system, the source said. The data surfaced on a dark web site on Saturday night, advertised as a cache of over 700 gigabytes, based on metadata analysis reviewed by Srikanth.
The incident adds to growing concern over cybersecurity risks facing large companies and financial institutions that store vast amounts of customer and business data.
This follows a string of recent breaches in India. In June, a cyberattack on Apple supplier Tata Electronics led to the leak of component design and specification documents linked to Apple and Tesla. Earlier this month the ransomware group World Leaks posted files related to India's largest nuclear power plant, Kudankulam on the dark web.