Bank of Baroda 1TB data breach linked to compromised employee email
MUMBAI: Bank of Baroda has suffered a cyber breach that reportedly exposed about 1TB of customer and internal data after an employee's email account was
MUMBAI: Bank of Baroda has suffered a cyber breach that reportedly exposed about 1TB of customer and internal data after an employee's email account was compromised, the public sector lender said. The leaked files include branch audit reports, loan appraisal files, vigilance records and customer account-opening forms, among other documents circulating online. The bank said its core banking systems were not accessed and has launched a forensic investigation. The archive is said to contain savings and current account records, loan documents, NetBanking user details, Aadhaar numbers, NRI and corporate banking records, customer support files, and branch- and ATM-related information. Quick answers to key questions • 5 QUESTIONS 1 What caused the Bank of Baroda data breach? ⌵ The data breach was caused by the compromise of an employee's email account, which allowed unauthorized access to various internal and customer data. 2 What types of data were exposed in the Bank of Baroda breach? ⌵ The breach exposed approximately 1TB of data, including customer account-opening forms, loan documents, savings and current account records, and sensitive operational details. 3 Why is the Bank of Baroda breach considered a serious threat despite core systems remaining secure? ⌵ Even though core banking systems were not accessed, the exposure of personally identifiable information poses a risk for identity theft, fraudulent activities, and future cyberattacks. 4 How did the Bank of Baroda respond to the data breach?
⌵ The bank activated its cyber incident response protocols, launched a forensic investigation, and is cooperating with relevant authorities to assess the breach's scope. 5 Should Bank of Baroda customers be concerned about the breach? ⌵ Yes, customers should be concerned as their personal information might be used for malicious activities like identity theft or fraudulent loan applications. The breach came to light on 25 July after it was flagged by dark web monitoring platform ransomware.live, said Srikanth Lakshmanan, founder of fintech consumer collective CashlessConsumer. He said he verified a range of internal documents, including branch audit reports, loan appraisal files, internal communications, vigilance investigation records, bobWorld audit reports and customer account-opening forms from multiple branches. Also Read | BookMyForex denies data leak claims, says customer funds are safe In a filing to the exchanges later on Monday, Bank of Baroda said it had received a communication from an anonymous source claiming access to certain data, and had activated its cyber incident response and containment protocols. It has engaged an independent CERT-In empanelled agency to assess the nature and extent of the alleged compromise. The filing described the incident as a "potential business email compromise" that is "not expected to have any material impact on the Bank's operations, financial performance or business continuity". The stock exchanges had sought a clarification from the bank on a 27 July media report about the data appearing on the dark web, asking it to respond under Regulation 30 of the Sebi (Listing Obligations and Disclosure Requirements) Regulations, 2015, which governs the disclosure of material events.
