The state-owned lender has said its core banking systems were not accessed, but reports that customer data may have surfaced on the dark web may have raised questions over what the breach means for account holders.
Here’s what is known so far.What happened?
Bank of Baroda said an employee’s email account was compromised, resulting in unauthorised access to certain data. The bank has not disclosed what data was accessed or whether customer records were affected.
The statement followed media reports that customer information and internal bank documents had appeared on the dark web.
Reuters, citing a source familiar with the matter and cybersecurity researcher Srikanth L, reported that the leaked material includes customer details, identification documents, loan papers and internal audit records. The report added that the data was advertised as a cache containing more than 700 GB of information, although the number of affected customers is not known.
The bank has initiated a forensic investigation.
Is your bank account safe?
Based on the information disclosed by the bank, there is no indication that customer accounts or transactions have been compromised.
Bank of Baroda said its core banking systems were not accessed. These systems manage deposits, withdrawals, fund transfers and other banking transactions. The bank has not reported any unauthorised access to customer accounts.
If money isn’t at risk, why does the breach matter?
The concern relates to the possible exposure of personal information rather than direct access to bank accounts.
If customer data such as names, identification documents or loan records has been accessed, it could be used to target customers through phishing emails, fraudulent phone calls or identity theft. Such attempts typically involve criminals impersonating banks or other trusted organisations to obtain passwords, OTPs or other sensitive information.
Should customers take any action?
The bank has not asked customers to reset passwords or take any specific action.
However, cybersecurity experts generally advise customers to:
- Change internet and mobile banking passwords if the same password is used across multiple websites.
- Enable multi-factor authentication wherever available.
- Review account statements and transaction alerts regularly.
- Avoid sharing OTPs, PINs or passwords with anyone.
- Ignore calls, emails or messages seeking banking credentials or KYC details.
- Access banking services only through the official website or mobile app.
What happens next?
The forensic investigation is expected to establish how the breach occurred, what data was accessed and whether any customer information was compromised.
Until the findings are available, the exact impact of the incident remains unclear. The bank has maintained that its banking operations continue to function normally and that its core banking systems remain secure.
