Customer data from India’s Bank of Baroda leaked online, source and researcher say

Written by: Gopika Gopakumar and Ashwin Manikandan
MUMBAI, July 27 (Reuters) – Customer data and internal documents from India’s state-owned bank Baroda have been leaked onto the dark web, according to a source familiar with the matter and a cybersecurity researcher.
Cybersecurity researcher Srikanth L, founder of Cashless Consumer, said the leaked data included customer details, identity documents, credit documents and internal audit records.
A source familiar with the matter confirmed the leak and said the bank was conducting a forensic audit.
It was not immediately clear how many customers were affected. Bank of Baroda did not notify the stock exchanges of any violation.
Bank of Baroda, Reserve Bank of India and CERT-In, India’s cybersecurity regulator, did not immediately respond to requests for comment.
The leak comes at a time when concerns are growing about the cybersecurity risks faced by large companies and financial institutions that store large amounts of customer and business data.
The source said preliminary indications are that the incident was caused by a compromised email system.
Srikanth said the data appeared on a dark website on Saturday night and was promoted as a cache containing more than 700 gigabytes of information, based on the site’s metadata analysis.
In June, a cyberattack on Apple supplier Tata Electronics led to component design and specification documents linked to Apple and Tesla being leaked on the dark web.
Earlier this month, ransomware group World Leaks published files related to India’s largest nuclear power plant on the dark web.
(Reporting by Gopika Gopakumar and Ashwin Manikandan. Editing by Mark Potter)




