Bank of Baroda has reported an employee email compromise resulting in unauthorized data access, though the bank emphasizes its core banking systems are secure. A hacking group named TripleX has claimed responsibility for leaking depositor details, including customer application forms and identity documents, onto the dark web. The bank is conducting a forensic investigation and cooperating with authorities to address the incident and protect customer data.

Bank of Baroda has reported an employee email compromise resulting in unauthorized data access, though the bank emphasizes its core banking systems are secure. A hacking group named TripleX has claimed responsibility for leaking depositor details, including customer application forms and identity documents, onto the dark web. The bank is conducting a forensic investigation and cooperating with authorities to address the incident and protect customer data.

Bank of Baroda has reported an employee email compromise resulting in unauthorized data access, though the bank emphasizes its core banking systems are secure. A hacking group named TripleX has claimed responsibility for leaking depositor details, including customer application forms and identity documents, onto the dark web. The bank is conducting a forensic investigation and cooperating with authorities to address the incident and protect customer data.

State-owned Bank of Baroda, in an official announcement, reported that an employee's email was compromised and unauthorised data access was suspected after the incident.

However, the bank informed that the perpetrators have not accessed its core banking systems, which remain secure.

"The Bank has robust information security protocols in place. The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The Bank's core banking systems were not accessed and continue to remain secure," the bank said in a post on X (formerly Twitter).

The bank assured the depositors that a comprehensive forensic investigation had been initiated and that it is working closely with the relevant authorities in accordance with applicable regulatory requirements.

As per Moneycontrol, a hacking group named TripleX has taken responsibility for publishing the depositor details online. A listing on July 24 on the dark web monitoring platform Ransomware. live, alleges that the dataset includes between 100,000 and 300,000 customer application forms containing photographs and identity documents submitted during account opening. Apart from this, details regarding Aadhaar, NetBanking details, savings & current account details, etc are suspected to have been leaked. The hacking group has claimed to have leaked 1TB (1,000GB) of sensitive customer and banking details on the dark web.

Meanwhile, shares of Bank of Baroda closed at ₹244.20, marking a decrease of 0.99 per cent during the trading session on Monday. The lender also reported a 72 per cent year-on-year drop in net profit to ₹1,278 crore for the first quarter of FY27.