July 28, 2026
One Inbox, One Terabyte: What the Bank of Baroda Leak Actually Tells Us

By Ayush Bagde
5 min read
There's a version of this story where a shadowy hacking collective defeats a bank's defenses with sophisticated tooling. That's not this story. This story, as far as anyone can tell right now, starts with one employee's email account and if you believe the attackers, a weak password.
On July 24, 2026, India's second largest public sector bank appeared on the leak site of a group calling itself Triple X. The claim: roughly one terabyte of Bank of Baroda data, posted on a Tor server as an open, browsable directory. Not auctioned. Not held for ransom. Just… published, free, for anyone who cared to look.
That last detail is what makes this incident worth sitting with.
How it surfaced
The listing was picked up by ransomware.live, a Dark Web monitoring platform, and over that weekend it caught the attention of Srikanth Lakshmanan, the researcher behind CashlessConsumer. He did what good researchers do: downloaded samples, verified what he could, and raised the alarm publicly on X. His verdict to India Today was blunt – "It's a cyber disaster."
What he found in the samples wasn't abstract. Branch audit reports. Loan appraisal documents. Vigilance investigations. Internal communications. Audit reports for bobWorld, the bank's mobile app. And the part that should worry ordinary customers are account-opening application forms, complete with photographs, Aadhaar and PAN copies, and address proofs, from branches across the country. Early metadata analysis of the dump directory counted over 92,000 files; estimates of the customer application forms alone run between one and three lakh.
To be careful about what's verified and what isn't: the bank has not confirmed the contents of the dump. The figures above come from researcher analysis of file names, directory structure, and verified samples — indicative, not exhaustive. Even the headline "1 TB" is the attacker's number; the listing Srikanth analyzed advertised something over 700 GB.
What the bank says
Bank of Baroda's statement came on Monday, July 27 — three days after the listing went up. The core of it: "The incident involved compromise of an employee's email account, resulting in unauthorised access to certain data." The bank says the matter was promptly identified, containment measures were implemented, and the line every bank reaches for "core banking systems were not accessed and remain secure".
In its regulatory filing, the bank characterized the incident as a potential business email compromise, said it had engaged a CERT-In / RBI-empanelled agency for forensic investigation, and stated the incident is not expected to have any material impact on operations or financials.
All of that may be true. And it can be true at the same time that a serious amount of sensitive customer paperwork is now permanently public. "Core banking was not touched" and "your KYC documents are on Tor" are not mutually exclusive sentences and that's the tension regulators and customers will be living with as the investigation unfolds.
One more uncomfortable timeline detail: ransomware.live's tracking estimates the initial compromise around May 12. If that holds up, the attacker had access for more than two months before anyone noticed a dwell time that a forensic investigation will need to explain.
Who is Triple X?
A young group. Threat Intelligence trackers first observed them around May to June 2026, with just three known victims so far clustered in financial services. In May, they hit PT Bank Negara Indonesia, one of Indonesia's largest state owned banks, and dumped 2 TB of data the same way: full public release on a Tor site.
That's the pattern that breaks the usual ransomware playbook. Most extortion groups steal data and threaten to leak it, because the threat is the product. Triple X, in both known bank cases, skipped the negotiation and published everything for free. In posts on their leak site, they framed the Bank of Baroda dump as punishment for weak passwords and sloppy security. Whether that's genuine ideology or theater, the practical effect is worse for victims: there's no ransom that buys the data back, and no delay while negotiations happen. Exposure is immediate and total.
A note of honesty about attribution: no one has formally, verifiably claimed the attack, and the bank hasn't named an actor. The Triple X attribution rests on the leak-site listing itself. That's reasonably strong evidence but it's a claim, not a forensic finding.
What about IOCs?
If you came looking for hashes, IPs, and malware signatures: as of this writing, there are none published. This appears to have been credential driven access to a mailbox, not a malware campaign, so the "indicators" are unglamorous:
-
Initial vector: business email compromise of a single employee account; the attackers publicly attributed access to a weak password.
-
Infrastructure: the Triple X data-leak site and an open Tor directory index hosting the full dump, tracked via ransomware.live.
-
Target reference: the listing names bankofbaroda.bank.in.
-
Pattern: pure data-theft extortion, no encryption event reported; notably, trackers observe prior infostealer exposure in roughly two-thirds of this group's victims, A reminder that stolen credentials, not zero-days, remain the front door.
The regulatory clock is ticking
India's rules give banks very little time. CERT-In requires specified cyber incidents to be reported within six hours of awareness. RBI's Cyber Security Framework gives banks two to six hours for an initial report. Whether Bank of Baroda met those windows and whether its controls met RBI's requirements in the first place is exactly what regulators will now examine, with monetary penalties on the table under the Banking Regulation Act if lapses are established.
The bigger stick, the Digital Personal Data Protection Act's breach-notification and penalty regime (up to ₹200 crore), doesn't fully bite until May 2027. This incident is a preview of how Indian financial institutions will fare under that regime and the three-day gap between listing and public statement is the kind of thing DPDP-era rules are designed to compress.
Reports also indicate the bank has filed a preliminary notification under a cyber-insurance programme with total cover of about ₹750 crore. No claim value has been established.
If you bank with BoB
Your money is not known to be at direct risk. This was documents, not payment systems. The real threat is downstream: fraudsters who now potentially hold your name, photo, Aadhaar, branch, and loan details can run devastatingly convincing phishing and vishing campaigns.
The practical moves, in line with CERT-In's standing advisory:
-
Change your NetBanking and mobile banking passwords, especially if reused anywhere else.
-
Turn on transaction alerts and actually read them.
-
Treat every inbound call or message "from the bank" asking you to verify anything as hostile — hang up and call the official number.
-
Watch for loans or accounts you didn't open; consider checking your credit report.
The lesson nobody wants to hear
Banks spend enormous sums hardening core banking systems, and by all current evidence, that hardening held here. What failed was the boring perimeter: one mailbox, one credential, allegedly one weak password and about two months of nobody noticing.
Aadhaar numbers can't be rotated like passwords. A leaked KYC form is leaked forever. The uncomfortable truth of this breach isn't that a bank got hacked; it's that the blast radius of a single inbox turned out to be a terabyte wide.
Facts as of July 28, 2026, cross-checked across the bank's public statement and regulatory filing, Reuters, The Record (Recorded Future News), ISMG/GovInfoSecurity, ransomware.live, and CashlessConsumer's ongoing bobbreach analysis. The contents of the dump are researcher-verified samples and metadata analysis, not bank-confirmed; this piece separates claims from confirmations accordingly.