Connect with us

Infosecurity

Bank of Baroda confirms cyber incident after hacker claims massive data theft

Published

on

Bank of Baroda cyber incident

Bank of Baroda employee email compromised

One of India’s largest public-sector banks, Bank of Baroda, has confirmed a cybersecurity incident after a threat actor claimed to have stolen and published sensitive banking data. The bank said Monday that an employee’s email account was compromised, giving unauthorized access to “certain data.”

The bank said it detected and contained the incident immediately. Core banking systems were not accessed or affected, it added. An investigation is ongoing.

The disclosure follows claims last week by multiple cybersecurity researchers tracking dark web activity. An unidentified hacker breached the bank and leaked what it described as customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum.

The authenticity of the leaked data could not be independently verified. Bank of Baroda did not comment on the hackers’ claims or say whether any customer data was exfiltrated. It also did not attribute the incident to any specific hacking group.

Researchers said the threat actor, operating under the name “leak-king-F,” advertised the data for sale on a popular darknet marketplace and directed prospective buyers to a Telegram channel.

What was stolen in the Bank of Baroda cyber incident?

The hacker claims to have stolen a trove of sensitive data. The leaked files allegedly include customer information, corporate banking records, internal emails, loan documents and audit files. If confirmed, this would be one of the most significant data breaches at an Indian bank in recent years.

However, the bank’s statement suggests the breach was limited to an email account. That could mean the data accessed was not from core banking databases but from communications and attachments stored in the compromised mailbox.

Still, the potential for customer data exposure is serious. Email accounts often contain sensitive information exchanged with clients, partners and regulators.

leak-king-F: the hacker behind the attack

The threat actor calling themselves “leak-king-F” posted the stolen data on a darknet forum. They advertised it for sale and directed interested buyers to a Telegram channel. The group has not made any ransom demands public, unlike other extortion gangs active in the region.

This is not the first time a hacker has targeted a major Indian financial institution. In 2023, a ransomware attack on a state-owned bank disrupted services for days. But the Bank of Baroda incident stands out because of the volume and sensitivity of the data allegedly stolen.

Researchers are still analyzing the leaked files to verify their authenticity. The bank has not confirmed which specific data was accessed.

Financial institutions under siege across Asia

The Bank of Baroda cyber incident is the latest in a string of attacks on financial institutions across Asia. Last week, Thailand’s Securities and Exchange Commission launched an investigation into a data breach at the Thailand Securities Depository (TSD). Hackers claimed to have stolen investor information after compromising an investor portal.

Trading, settlement and depository systems were not affected, TSD said. But the breach exposed customer data and raised concerns about the security of financial infrastructure in the region.

Earlier this month, the ransomware and extortion group World Leaks published thousands of files it claimed were stolen from contractors working on India’s largest nuclear power project. India’s state-owned nuclear operator said the documents contained no information affecting the safety or security of the plant. The files appeared to originate from a third-party company building conventional infrastructure for new reactors.

World Leaks also claimed responsibility for an attack on Tata Electronics, a key supplier to Apple, Tesla and Qualcomm. The group demanded a $1.5 million ransom before publishing what it said were confidential engineering documents. Tata Electronics allegedly refused to negotiate.

What Bank of Baroda customers should do now

If you are a Bank of Baroda customer, here are a few steps to protect yourself:

  • Monitor your account statements for unauthorized transactions.
  • Change your online banking passwords and enable two-factor authentication.
  • Be cautious of phishing emails that may reference the breach.
  • Contact the bank’s customer service if you notice anything suspicious.

The bank has not reported any unauthorized transactions from customer accounts yet. But vigilance is always wise after a breach.

Lessons from the Bank of Baroda cyber incident

This incident highlights a critical vulnerability: employee email accounts. Even if core banking systems are secure, a compromised email can leak sensitive data. Financial institutions must invest in email security, including multi-factor authentication, encryption and employee training.

It also shows how quickly hackers can weaponize stolen data. The files were posted on a darknet forum within days of the breach. That leaves little time for the bank to respond or notify affected customers.

Regulators in India and across Asia will likely scrutinize the incident closely. If customer data was indeed stolen, Bank of Baroda could face fines and reputational damage.

The investigation is ongoing. For now, the bank says its core systems are safe. But the full extent of the damage may not be known for weeks.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Laundry Bear’s webmail hackers had more in store after February, report says

Published

on

Laundry Bear hackers

Laundry Bear’s second, stealthier wave

Researchers at Proofpoint say the Russian-linked hacking group known as Laundry Bear didn’t stop with its Zimbra attacks earlier this year. A day before a global alert went out in late July, the same crew was already exploiting a fresh bug in Microsoft Outlook Web Access (OWA).

The finding, published Wednesday, expands the timeline of a campaign that government agencies and cybersecurity firms first flagged on July 23. That initial warning centered on a vulnerability in Zimbra Collaboration Suite’s webmail platform, which Laundry Bear had abused as recently as February.

Now Proofpoint says the group — also tracked as TA488 and Void Blizzard — began targeting OWA users on July 22, the day before the international advisory. The victims: US and European government entities, plus organizations in telecom, finance, hospitality and aerospace.

Half-click exploits and a new implant called OWAReaper

The attack chain relied on “half-click” exploits, meaning that simply opening a malicious email was enough to trigger the infection. No further user action was required.

Proofpoint described the payload as a JavaScript browser-based backdoor it named OWAReaper. The researchers called it “the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing,” citing its suite of subtle persistence mechanisms.

Greg Lesnewich, one of the report’s authors, posted on social media that OWAReaper was “one of the coolest implants we’ve ever examined.”

Zero-day potential

The researchers said it’s “feasible” that Laundry Bear was exploiting the OWA vulnerability as a zero-day — meaning the group had found and weaponized the bug before Microsoft was even aware of it. The flaw, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted remediation guidance in mid-July, months after the group allegedly began laying groundwork for the campaign in March.

An upgrade in tradecraft

Proofpoint assessed that the malware campaign represented “an improvement in the group’s tradecraft and capability.” The goal remained the same as the Zimbra operation: steal emails and account credentials. But the method evolved.

Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. US prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.

The OWAReaper campaign shows that Laundry Bear is adapting its toolkit and expanding its target list. For organizations still running unpatched OWA instances, the window for protection is narrowing.

What comes next

Proofpoint acknowledged that it didn’t have enough time to include the July 22 discovery in its initial alert. The update now gives defenders a fuller picture of the group’s recent activity.

Security teams should prioritize patching both Zimbra and OWA vulnerabilities, monitor for half-click exploit indicators, and review accounts for unusual OWA session behavior. The half-click vector makes traditional user training less effective — the infection starts before the user can make a choice.

Laundry Bear’s persistence and growing sophistication suggest that webmail platforms will remain a prime target for state-backed espionage. The group’s ability to pivot from Zimbra to OWA within months signals a flexible, well-resourced operation.

For now, OWAReaper is the group’s most advanced tool. Whether it’s the last remains an open question.

Continue Reading

Infosecurity

Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

Published

on

Phishing initial entry method

Phishing Surges as the Top Attack Vector

Phishing has reclaimed its spot as the number one way cyber-attacks begin. According to a new report from Cisco Talos, covering March through June 2026, phishing was the initial entry method in just over half of all incidents that required professional remediation.

That’s a sharp jump from the previous quarter, when phishing accounted for only a third of cases. The report, published July 28, makes clear: attackers are doubling down on social engineering — and they’re getting better at it.

Other common entry points included exploitation of public-facing applications and drive-by compromise attacks, where a user simply visits a booby-trapped website. But phishing was the clear leader.

The QR Code Twist: A New Kind of Bait

Why the spike? Attackers are experimenting with fresh tools and techniques designed to slip past defenses. One standout example: a QR code phishing campaign targeting organizations to steal Microsoft 365 credentials.

Here’s how it works. The attacker, tracked by Cisco Talos as UAT-11764, auto-generates PDF documents tailored to each victim. Inside the PDF: a QR code. Scan it, and you land on a credential harvesting page hosted on a trusted cloud platform like SharePoint or Microsoft 365.

Two things make this tricky to stop. First, traditional email gateways often don’t flag QR codes as malicious — they’re just images. Second, the phishing pages live on legitimate infrastructure, so they don’t trigger typical security alerts.

Once the attacker has the credentials, they don’t stop at inbox access. They create email inbox rules to hide their tracks, then use the compromised account to blast more phishing emails to the victim’s contacts. The campaign was still active as of late June 2026.

“By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, UAT-11764 can bypass many standard email security gateways,” the report warns. Defenders are advised to block or flag emails containing QR codes inside PDF attachments, enforce phishing-resistant multi-factor authentication, and watch for suspicious inbox rule creation.

Phishing-as-a-Service: Crime Made Easy

The report also highlights the growing sophistication of phishing-as-a-service (PhaaS) kits. These are off-the-shelf toolkits that let almost anyone run a phishing campaign — no coding skills required.

Modern PhaaS platforms come with a full suite of post-compromise tools. Capabilities observed during the period include:

  • Automated token management
  • Persistent access through Primary Refresh Tokens (PRTs)
  • OneDrive and SharePoint administration
  • Geo-dynamic templates that change the phishing page based on the victim’s location
  • Inbox rule manipulation
  • Cross-account keyword monitoring
  • Collaborative token sharing among attackers

Some kits can even bypass MFA by abusing the OAuth device authorization flow — a technique that doesn’t steal passwords but tricks the authentication process itself.

Researchers also found advanced anti-analysis features, including layered evasion mechanisms and encrypted client-side payloads. The report calls this “the increasing sophistication of modern PhaaS platforms.”

How to Defend Against These Evolving Threats

Cisco Talos offers concrete steps for organizations trying to stay ahead. The advice is practical, not theoretical:

  • Deploy phishing-resistant MFA — and configure it properly. Not all multi-factor authentication is equal.
  • Centralize your logging with adequate retention. You can’t detect what you don’t record.
  • Patch aggressively and reduce your exposed infrastructure. Fewer doors mean fewer entry points.
  • Set strict outbound email thresholds to limit how many messages a single account can send. This can stop a compromised mailbox from becoming a spam cannon.

The takeaway? Phishing isn’t going away. But with the right defenses — and awareness that attackers are constantly refining their methods — organizations can make themselves a much harder target.

Continue Reading

Infosecurity

Google Drops Massive Chrome 151 Update: 370 Vulnerabilities Patched, 7 Critical

Published

on

Chrome 151 vulnerabilities

Google’s biggest Chrome security update of the year just landed

On July 29, Google dropped patches for a staggering 370 security vulnerabilities in Google Chrome. That’s not a typo — three hundred and seventy flaws, seven of them rated critical. The update pushes the browser to version 151 for Windows, Mac (151.0.7922.71/.72), and Linux (151.0.7922.71).

For context, the typical monthly Chrome update addresses somewhere between 20 and 50 bugs. This one is nearly ten times that. It’s the kind of patch cycle that makes security teams sit up — and makes you want to check your browser version right now.

What’s inside the Chrome 151 patch: 7 critical CVEs

The seven critical vulnerabilities all involve memory management or input validation issues. Google’s internal security researchers reported them between May 18 and June 14, 2026. Here’s the breakdown:

  • CVE-2026-17650 — Use after free in Compositing (reported May 18)
  • CVE-2026-17651 — Insufficient validation of untrusted input in Dawn (May 28)
  • CVE-2026-17652 — Use after free in Views (June 2)
  • CVE-2026-17653 — Use after free in Skia (June 5)
  • CVE-2026-17654 — Race condition in the Updater (June 10)
  • CVE-2026-17655 — Insufficient validation of untrusted input in ANGLE (June 11)
  • CVE-2026-17656 — Use after free in Ozone (June 14)

“Use after free” bugs are a classic memory corruption pattern. A program tries to access memory after it’s been freed, which can let an attacker run arbitrary code. They’re the kind of flaw that browser makers dread — and that exploit developers love.

Dawn and ANGLE: The graphics pipeline under scrutiny

Two of the critical bugs hit graphics-related components. CVE-2026-17651 targets Dawn, Google’s WebGPU implementation. CVE-2026-17655 affects ANGLE, the open-source translation layer that converts OpenGL ES calls into Vulkan, DirectX, or Metal. ANGLE is what lets Chrome run 3D graphics smoothly across different hardware without requiring special drivers. A flaw there could potentially allow an attacker to corrupt GPU memory or crash the renderer.

The Updater race condition (CVE-2026-17654) is worth noting too. The auto-update mechanism is a critical part of Chrome’s security posture — a bug in the updater itself is the kind of irony that keeps security engineers up at night.

By the numbers: 71 high, 170 medium, 122 low

Beyond the critical seven, the patch batch includes 71 high-severity fixes, 170 medium-severity patches, and 122 low-severity corrections. That’s a lot of ground covered. Some of the medium-severity bugs might sound less scary, but in combination with other flaws, they can become dangerous. Google doesn’t release full technical details for most bugs until users have had time to update.

Security researchers who reported these flaws collected a combined $58,500 through Google’s bug bounty program. However, the company hasn’t disclosed payout details for 13 of the bugs yet — possibly because some are still under review or involved higher-tier rewards.

How to update Chrome right now

If you haven’t updated yet, here’s what to do:

  • Click the three-dot menu in the top-right corner of Chrome
  • Go to HelpAbout Google Chrome
  • Chrome will automatically check for updates and install version 151
  • Restart the browser to complete the update

That’s it. The whole thing takes about two minutes. Given the scale of this patch, it’s time well spent.

This update follows a busy year for Chrome security. In 2025, Google issued multiple emergency patches for Chrome zero-day vulnerabilities, including one in January and another in March. While this July update doesn’t mention any zero-days being actively exploited, the sheer volume of fixes suggests the Chrome security team has been working overtime.

Google’s message: Prevention, not just reaction

In its release notes, Google thanked “all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.” That’s a subtle but important shift — it means some of these bugs were caught internally or through partnerships before they could be exploited in the wild.

Still, 370 vulnerabilities in a single release is a lot. It raises the question: is Chrome getting more complex, or are researchers getting better at finding its weak spots? Probably both. As the browser adds features — GPU compute, WebGPU, advanced rendering — the attack surface grows. The good news is that Google’s bug bounty program is clearly working, and patches are being shipped fast.

Version 151 is rolling out now. Make sure you’re running it before you browse any further.

Continue Reading

Trending