Bank of Baroda probes alleged 1 TB data theft after employee email compromise

Bank of Baroda said an employee email compromise enabled unauthorised access to certain data, while its core banking systems remained secure. A threat actor has claimed to hold about 1 TB of bank-linked customer and corporate records; the bank has ordered a forensic investigation.

— Source publishedMon, 27 Jul, 2026, 17:51 IST·First seen Mon, 27 Jul, 2026, 20:02 IST·Source The Hindu BusinessLine

What happened

Bank of Baroda said an employee email compromise enabled unauthorised access to certain data, while core banking systems remained secure. A threat actor has

Key facts

  • Approximately 1 TB of alleged data

Why this matters

For banking partners, vendors and acquisition targets, the incident reinforces the need to diligence email security, identity controls, data segmentation and breach-response maturity beyond core banking-system resilience.

What to watch

  • Whether the bank confirms the categories, volume and date range of exposed data.
  • Publication of credible data samples containing customer identifiers, account details, KYC files or corporate records.
  • RBI, CERT-In or stock-exchange disclosures requiring formal incident updates.
  • A rise in customer phishing reports, account-takeover attempts or fraudulent beneficiary additions referencing bank-specific information.
  • Evidence that cloud drives, shared mailboxes, backup systems or vendor portals were accessed beyond one employee account.
  • Changes in management guidance on cybersecurity spending, legal provisions or operational disruption.
  • Force password resets and revoke active sessions for employees, privileged users and connected SaaS accounts.
  • Engage external forensic investigators to reconstruct mailbox access, cloud-storage exposure, data exfiltration paths and lateral movement.
  • Notify RBI, CERT-In and affected counterparties as required; prepare customer communications if data exposure is confirmed.
  • Increase monitoring for phishing, SIM-swap attempts, credential stuffing and suspicious payment-beneficiary changes targeting Bank of Baroda customers.
  • Audit third-party vendors, email forwarding rules, OAuth applications, backup repositories and data-loss-prevention controls.
  • Threat actor may release data samples or seek extortion to substantiate the 1 TB claim.