Bank of Baroda Confirms Data Breach as Triple X Ransomware Group Claims 1TB Leak
Bank of Baroda disclosed a significant data breach on Monday after the Triple X ransomware group asserted it had exfiltrated 1TB of sensitive data, now reportedly accessible in a public dump. The leaked files spanning 9,783 directories and over 92,000 documents include customer KYC records, internal security reports, and audit materials, raising concerns about potential misuse.
In an official statement on X (formerly Twitter), the bank confirmed the incident stemmed from the compromise of an employee’s email account, which granted unauthorized access to certain data. However, it emphasized that core banking systems remained secure, with no evidence of breach. Immediate containment measures were enacted, and a forensic investigation is underway in collaboration with regulatory authorities.
Cybersecurity experts described the breach as "concerning for the banking ecosystem", noting that while the exposed data likely originated from internal SharePoint or file-sharing systems rather than the bank’s Finacle core banking platform the leak still poses substantial risks. The incident underscores broader vulnerabilities in financial institutions handling vast troves of sensitive data.
This breach follows recent high-profile attacks, including a June cyberattack on Tata Electronics that leaked proprietary designs linked to Apple and Tesla, and a ransomware group’s dark web post earlier this month exposing files from India’s largest nuclear plant. The pattern highlights escalating threats to critical infrastructure and corporate data security.
India's largest nuclear plant TPRM report: https://www.rankiteo.com/company/bank-of-baroda-india's-international-bank
Tata Electronics TPRM report: https://www.rankiteo.com/company/tatasteelltd
"id": "tatban1785228073",
"linkid": "tatasteelltd, bank-of-baroda-india's-international-bank",
"type": "Ransomware",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'India',
'name': 'Bank of Baroda',
'type': 'Bank'}],
'attack_vector': 'Compromised employee email account',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '9,783 directories and over '
'92,000 documents',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Customer KYC records',
'Internal security reports',
'Audit materials']},
'description': 'Bank of Baroda disclosed a significant data breach after the '
'Triple X ransomware group asserted it had exfiltrated 1TB of '
'sensitive data, now reportedly accessible in a public dump. '
'The leaked files include customer KYC records, internal '
'security reports, and audit materials.',
'impact': {'brand_reputation_impact': 'Substantial risks to brand reputation',
'data_compromised': '1TB of sensitive data',
'identity_theft_risk': 'High',
'systems_affected': 'Internal SharePoint or file-sharing systems'},
'initial_access_broker': {'entry_point': 'Compromised employee email account'},
'investigation_status': 'Forensic investigation underway',
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Triple X'},
'references': [{'source': 'Bank of Baroda official statement on X (Twitter)'}],
'regulatory_compliance': {'regulatory_notifications': 'Collaboration with '
'regulatory '
'authorities'},
'response': {'communication_strategy': 'Official statement on X (formerly '
'Twitter)',
'containment_measures': 'Immediate containment measures enacted',
'incident_response_plan_activated': 'Yes'},
'threat_actor': 'Triple X ransomware group',
'title': 'Bank of Baroda Data Breach by Triple X Ransomware Group',
'type': 'Data Breach, Ransomware'}