Customer data from India's state-run Bank of Baroda has been leaked on the dark web, according to a source and a cybersecurity researcher.

The leaked data includes customer details, identification documents, loan papers, and internal audit records, according to the researcher.

Bank of Baroda stated it started a forensic investigation and implemented initial containment measures. The breach involved a compromised employee email account, resulting in unauthorised access to certain data. The bank said core banking systems were not accessed and remain secure.

The data was advertised as a cache containing more than 700 gigabytes of information. Some sources report the leak as 1 terabyte, with discrepancies among reports.

The data appeared on a dark web site on Saturday night, according to the researcher.

Cybersecurity researcher Srikanth L – also referred to as Srikanth Lakshmanan – founder of Cashless Consumer, identified the leak and verified documents. Sample files from the alleged breach were posted on X by Lakshmanan. "It's a cyber disaster," he said.

No individual or group has publicly claimed responsibility for the Bank of Baroda data leak. Researcher Srikanth Lakshmanan suggested a newer hacking group known as TripleX could be involved.

TripleX allegedly breached PT Bank Negara Indonesia, one of Indonesia's largest state-owned banks, in May 2024, according to claim:11.

The leaked dataset includes Aadhaar numbers, names, loan records, NetBanking user details, NRI and corporate banking records, customer support material, and ATM records, according to claim:12.

The Reserve Bank of India and India's cybersecurity regulator CERT-In did not immediately respond to requests for comment. In June 2024, a cyberattack on Apple supplier Tata Electronics reportedly led to leaked documents on the dark web (claim:15), and earlier in July 2024, ransomware group World Leaks allegedly posted files related to India's largest nuclear plant on the dark web (claim:16).