Bank of Baroda confirmed a bank of baroda cyber incident on Monday, saying an employee email account was compromised and used to gain unauthorized access to “certain data.” The disclosure matters because the claim landed after cybersecurity researchers said a hacker was trying to sell what they described as sensitive bank records on a darknet forum.
The Indian state-owned lender said in a statement on X that it detected and contained the incident immediately. Bank of Baroda said its core banking systems were neither accessed nor affected, and that an investigation is still underway.
The bank did not say what data was accessed through the email account. It also did not say whether customer information was taken, and it did not name any hacking group or individual as responsible.
Was customer data stolen from Bank of Baroda?
That has not been confirmed. Cybersecurity researchers tracking dark web activity said last week that an unidentified hacker claimed to have breached Bank of Baroda and leaked data described as customer information, corporate banking records, internal emails, loan documents and audit files.
The authenticity of the files has not been independently verified. Bank of Baroda’s public statement did not address the hacker’s claims directly, which leaves a gap between what the bank has confirmed, an email compromise with access to some data, and what the alleged seller is advertising, a broader cache of banking records.
Researchers said the threat actor used the name “leak-king-F.” According to posts from researchers, the actor advertised the alleged data for sale on a darknet marketplace and pointed potential buyers to a Telegram channel.
What does it mean that core banking systems were not affected?
Core banking systems are the infrastructure banks use to run account balances, transactions and other central banking functions. Bank of Baroda’s statement that those systems were not accessed is a meaningful containment claim, but it does not by itself rule out exposure of documents, emails or other records reachable from a compromised employee mailbox.
Email compromises can be messy for exactly that reason. A single mailbox may hold attachments, customer correspondence, internal approvals or links to shared files, depending on the employee’s role and access. Bank of Baroda has not provided that level of detail.
Asian financial firms face more breach claims
The Bank of Baroda disclosure follows other recent cyber incidents involving financial institutions and major companies in Asia.
Thailand’s Securities and Exchange Commission opened an investigation last week into a breach at the Thailand Securities Depository after hackers claimed to have stolen investor information. The stock exchange said attackers compromised an investor portal and accessed customer data without authorization. TSD said its trading, settlement and depository systems were not affected.
Earlier this month, the ransomware and extortion group World Leaks published thousands of files it claimed came from contractors working on India’s largest nuclear power project. India’s state-owned nuclear operator said the files did not affect plant safety or security and appeared to come from a third-party company building conventional, non-nuclear infrastructure for new reactors.
World Leaks also claimed an attack on Tata Electronics, a supplier to Apple, Tesla and Qualcomm. The group demanded a $1.5 million ransom and later published what it said were confidential engineering documents after alleging that Tata Electronics refused to negotiate.
This story draws on original reporting from The Record.