Bank Of Baroda Data Allegedly Appears On Dark Web: What Should Customers Check After The 1TB Breach Claim?

Bank of Baroda customers are checking their accounts after reports claimed that a large cache of banking and identity records appeared on the dark web. The figure widely shared online is close to 1TB, although the bank has not verified that volume or disclosed how many customers may be affected.

On July 27, 2026, the public sector lender confirmed that one employee email account had been compromised, allowing unauthorised access to certain data. It said its core banking systems were not accessed and remained secure. That reduces fears of a direct takeover of the bank’s main transaction platform, but exposed documents could still help fraudsters run convincing phishing, loan, KYC and impersonation scams.

What Has Bank Of Baroda Confirmed About The Alleged Leak?

The first dark-web reports surfaced over the weekend after a threat actor advertised a large collection of Bank of Baroda files. A cybersecurity researcher cited by Reuters said metadata indicated more than 700GB, while other reports described the claim as nearly 1TB. The exact size, authenticity of every file and number of affected customers remain unconfirmed.

The bank said containment steps were taken and a forensic investigation had begun with relevant authorities. Reports also said it had notified insurers under a cyber policy reportedly carrying about ₹750 crore of cover. Separately, The Indian Express shared the bank’s confirmation on X, providing an official news-account post that readers can follow for updates.

What Information Is Alleged To Be In The Dark-Web Files?

Researchers and media reports said samples may include customer details, identity documents, loan papers and internal audit records. Other unverified descriptions mention Aadhaar numbers, account information, NetBanking records, corporate and NRI service files, branch material and customer-support documents. Customers should not assume every category is genuine or that every account is affected.

Even when passwords, PINs and OTPs are not exposed, personal information can make scams look authentic. A caller may quote a branch, loan type, partial account number or address, then ask the customer to “verify” an OTP, install a remote-access application, approve a UPI collect request or move money to a so-called safe account. No genuine bank officer needs a customer’s PIN, CVV or OTP.

What Should Bank Of Baroda Customers Check Immediately?

Customers do not need to close accounts merely because a breach has been reported. They should instead review account activity, secure access and preserve proof of anything suspicious.

  • Check recent savings, current, card, loan and UPI transactions, including small test debits.
  • Change NetBanking and mobile-banking passwords, especially when the same password was reused elsewhere.
  • Confirm that the registered mobile number and email address are correct, then enable transaction alerts.
  • Reduce card, UPI and NetBanking limits temporarily when regular spending does not require higher limits.
  • Lock a card or digital channel immediately if an unknown transaction, login, or beneficiary appears.
  • Use the official UIDAI biometric lock service when Aadhaar misuse is a concern.
  • Check Sanchar Saathi for mobile connections issued in the customer’s name.
  • Report financial cyber fraud quickly through the National Cyber Crime Reporting Portal or helpline 1930.

Bank of Baroda’s login page advises customers to report unauthorised access promptly, contact the bank through official numbers and change passwords after suspected activity. Customers should type the bank address themselves or use its verified application, rather than opening links received through SMS, WhatsApp or email.

Speed is important after an unauthorised debit. The RBI customer-liability rules require customers to notify their bank quickly. Depending on how the transaction occurred and when it was reported, liability may be zero or limited. RBI also says the bank must provide a shadow reversal within 10 working days after notification in covered cases. Customers should obtain a complaint number and retain screenshots, statements, messages and call details.

Bank Of Baroda Data Breach FAQs

Has Bank Of Baroda Confirmed A 1TB Customer Data Leak?

No, it confirmed unauthorised email access but has not verified the claimed 1TB leak size.

Were Bank Of Baroda’s Core Banking Systems Hacked?

The bank said its core banking systems were not accessed and continue to remain secure.

Should Customers Change Their Bank Of Baroda Passwords?

Yes, changing unique banking passwords is sensible, especially when credentials were reused on other services.

Can Aadhaar Biometrics Be Locked After A Data Leak?

Yes, UIDAI allows holders to lock biometrics and temporarily unlock them whenever authentication is required.

Where Should Customers Report An Unauthorised Bank Transaction?

Report it immediately to Bank of Baroda, then call 1930 and file an online complaint.

Related Articles