Bank of Baroda has confirmed that a recent data leak resulting from a cyberattack was limited to information contained in a single employee's email account, and that the bank's core systems remain uncompromised.
Incident Details
The issue came to light after posts on social media platform X claimed that one terabyte of data, including personal Aadhaar details of customers, had been accessed. Internet security websites subsequently reported the availability of a dataset purportedly linked to the breach, according to a Business Today report.
Bank of Baroda stated: "The bank has robust information security protocols in place. The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data. The matter was promptly identified, and immediate containment measures were implemented. The bank's core banking systems were not accessed and continue to remain secure."
Response and Investigation
The bank said a comprehensive forensic investigation has been initiated and that it is working with relevant authorities in accordance with regulatory requirements, adding that it remains committed to maintaining information security standards and safeguarding customer interests.
External Monitoring
Srikanth Lakshmanan, founder of Cashless Consumer, a consumer collective working on digital payments to increase awareness, said the exposed dataset, still accessible a day after the breach, contained:
- Customer details such as names and contact information
- Banking-related data fields linked to accounts
- Identity-related information including Aadhaar-linked data
- Internal documents from the bank's systems
He noted the dataset was downloadable via an active link and shared sample screenshots indicating access.
Claims vs. Bank's Response
| Claim | Bank's Response |
|---|---|
| 1TB of data including Aadhaar details accessed | Compromise limited to one employee's email; core systems not accessed |
| Data available on internet security websites | Immediate containment measures implemented; forensic investigation initiated |
| Potential risk to customer data | Customer interests safeguarded; working with authorities |
Implications for Corporate Clients
For finance executives and treasury professionals, the incident highlights the critical importance of email security within banking institutions. Although Bank of Baroda assured that core banking systems were not affected, the leak of internal documents and customer data could still pose risks for business continuity and regulatory compliance. The bank's swift containment measures and forensic investigation aim to mitigate further exposure, but the episode serves as a reminder of the evolving cybersecurity landscape facing the financial sector.