Bank of Baroda confirms employee email compromise behind reported data breach

Bank of Baroda said an employee email account was compromised, enabling unauthorised access to certain data. A ransomware group claims it published roughly 1 TB of records, including customer KYC, loan, audit and internal files; the bank said core banking systems were not accessed.

— Source publishedMon, 27 Jul, 2026, 16:20 IST·First seen Mon, 27 Jul, 2026, 16:37 IST·Source Financial Express · BrandWagon

What happened

Bank of Baroda confirmed an employee email compromise led to unauthorised access to certain data. A ransomware group claims to have published about 1 TB of

Key facts

  • 1 TB of data
  • over 92,000 files
  • 9,783 directories
  • approximately five years of records

Why this matters

Any partnership or acquisition involving the bank should include deeper diligence on identity security, data governance, breach liabilities and third-party access controls.

What to watch

  • Independent confirmation that the alleged 1 TB dataset is authentic, current and includes identifiable customer records.
  • Bank disclosure of affected-record counts, specific data categories, dates of exposure and whether any downstream systems were accessed.
  • Regulatory notices, mandated remediation, fines or directions from RBI, CERT-In or data-protection authorities.
  • A rise in phishing, SIM-swap, loan-fraud or account-takeover reports tied to Bank of Baroda customer information.
  • Evidence that the breach involved cloud email configuration, inadequate MFA, mailbox forwarding rules, shared credentials or a third-party provider.
  • Further ransomware-group releases, sale listings or public samples that increase pressure for customer notification.
  • Disclose the scope, age, sensitivity and number of affected customer, employee and internal records after forensic validation.
  • Notify regulators and impacted customers promptly, with fraud-monitoring and anti-phishing guidance focused on KYC and loan-data misuse.
  • Reset credentials, revoke active sessions, audit mailbox forwarding rules and deploy phishing-resistant MFA for high-risk roles.
  • Review data-access permissions, email retention, encryption and controls over bulk export of audit, loan and KYC files.
  • Prepare customer-service, branch and digital-channel teams for increased fraud queries and social-engineering attempts using leaked data.
  • Expect peer banks, NBFCs, insurers and fintech partners to reassess employee-email and third-party access controls.