Bank of Baroda employee email compromised
One of India’s largest public-sector banks, Bank of Baroda, has confirmed a cybersecurity incident after a threat actor claimed to have stolen and published sensitive banking data. The bank said Monday that an employee’s email account was compromised, giving unauthorized access to “certain data.”
The bank said it detected and contained the incident immediately. Core banking systems were not accessed or affected, it added. An investigation is ongoing.
The disclosure follows claims last week by multiple cybersecurity researchers tracking dark web activity. An unidentified hacker breached the bank and leaked what it described as customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum.
The authenticity of the leaked data could not be independently verified. Bank of Baroda did not comment on the hackers’ claims or say whether any customer data was exfiltrated. It also did not attribute the incident to any specific hacking group.
Researchers said the threat actor, operating under the name “leak-king-F,” advertised the data for sale on a popular darknet marketplace and directed prospective buyers to a Telegram channel.
What was stolen in the Bank of Baroda cyber incident?
The hacker claims to have stolen a trove of sensitive data. The leaked files allegedly include customer information, corporate banking records, internal emails, loan documents and audit files. If confirmed, this would be one of the most significant data breaches at an Indian bank in recent years.
However, the bank’s statement suggests the breach was limited to an email account. That could mean the data accessed was not from core banking databases but from communications and attachments stored in the compromised mailbox.
Still, the potential for customer data exposure is serious. Email accounts often contain sensitive information exchanged with clients, partners and regulators.
leak-king-F: the hacker behind the attack
The threat actor calling themselves “leak-king-F” posted the stolen data on a darknet forum. They advertised it for sale and directed interested buyers to a Telegram channel. The group has not made any ransom demands public, unlike other extortion gangs active in the region.
This is not the first time a hacker has targeted a major Indian financial institution. In 2023, a ransomware attack on a state-owned bank disrupted services for days. But the Bank of Baroda incident stands out because of the volume and sensitivity of the data allegedly stolen.
Researchers are still analyzing the leaked files to verify their authenticity. The bank has not confirmed which specific data was accessed.
Financial institutions under siege across Asia
The Bank of Baroda cyber incident is the latest in a string of attacks on financial institutions across Asia. Last week, Thailand’s Securities and Exchange Commission launched an investigation into a data breach at the Thailand Securities Depository (TSD). Hackers claimed to have stolen investor information after compromising an investor portal.
Trading, settlement and depository systems were not affected, TSD said. But the breach exposed customer data and raised concerns about the security of financial infrastructure in the region.
Earlier this month, the ransomware and extortion group World Leaks published thousands of files it claimed were stolen from contractors working on India’s largest nuclear power project. India’s state-owned nuclear operator said the documents contained no information affecting the safety or security of the plant. The files appeared to originate from a third-party company building conventional infrastructure for new reactors.
World Leaks also claimed responsibility for an attack on Tata Electronics, a key supplier to Apple, Tesla and Qualcomm. The group demanded a $1.5 million ransom before publishing what it said were confidential engineering documents. Tata Electronics allegedly refused to negotiate.
What Bank of Baroda customers should do now
If you are a Bank of Baroda customer, here are a few steps to protect yourself:
- Monitor your account statements for unauthorized transactions.
- Change your online banking passwords and enable two-factor authentication.
- Be cautious of phishing emails that may reference the breach.
- Contact the bank’s customer service if you notice anything suspicious.
The bank has not reported any unauthorized transactions from customer accounts yet. But vigilance is always wise after a breach.
Lessons from the Bank of Baroda cyber incident
This incident highlights a critical vulnerability: employee email accounts. Even if core banking systems are secure, a compromised email can leak sensitive data. Financial institutions must invest in email security, including multi-factor authentication, encryption and employee training.
It also shows how quickly hackers can weaponize stolen data. The files were posted on a darknet forum within days of the breach. That leaves little time for the bank to respond or notify affected customers.
Regulators in India and across Asia will likely scrutinize the incident closely. If customer data was indeed stolen, Bank of Baroda could face fines and reputational damage.
The investigation is ongoing. For now, the bank says its core systems are safe. But the full extent of the damage may not be known for weeks.