In the quiet architecture of trust that holds modern banking together, a fracture has appeared: a hacking group called TripleX has allegedly placed over a terabyte of Bank of Baroda's most sensitive data onto the dark web, exposing the Aadhaar numbers, account credentials, and loan records of millions of Indians. The breach, surfacing on July 25th, strikes at the intersection of identity and finance — two systems that, in India, have been deliberately fused into one. As the bank and its regulators remain silent, the people most affected are left to navigate uncertainty alone, without warning,
Bank of Baroda suffers massive 1TB data breach; customer details, Aadhaar numbers exposed
The data is already in the wild, free for download on the dark web.
When you say 1TB of data, what does that actually mean in terms of how many people are affected?
We don't have an exact customer count in the reporting, but Bank of Baroda serves millions. The breach includes records from multiple branches across the entire country, so we're talking about a very large population exposed.
Why is Aadhaar exposure particularly dangerous compared to, say, just account numbers?
Aadhaar is a biometric identifier linked to your identity, taxes, bank accounts, and government benefits. If someone has your Aadhaar plus your account details, they have enough to impersonate you across multiple systems. It's not just one account at risk—it's your entire financial identity.
The bank hasn't said anything yet. Is that normal?
It's common for institutions to stay quiet initially while they assess the damage, but it's also dangerous. Customers don't know if they should change passwords, monitor their accounts, or file fraud reports. The silence creates a vacuum where panic and misinformation can spread.
This TripleX group—are they trying to sell the data or just cause chaos?
In this case, they made it freely available on the dark web rather than auctioning it. That's unusual. It suggests either they're making a statement, or they're confident enough in their capabilities that they don't need the ransom money. Either way, it's more destructive than a traditional extortion attack.
What should a Bank of Baroda customer do right now?
Without official guidance from the bank or RBI, they're in a difficult position. Ideally, they'd monitor their accounts closely, consider changing passwords, and watch for suspicious activity. But the bank should be proactively notifying people and offering credit monitoring or fraud protection. That hasn't happened yet.
O Pulso
- A terabyte of stolen data — Aadhaar numbers, NetBanking credentials, loan files, internal audits — is already freely downloadable on the dark web, meaning the window to prevent misuse has effectively closed.
- Independent researcher Srikanth Lakshmanan verified the breach himself, publicly sharing sample documents on X that confirmed the leak was live and devastatingly specific, calling it 'a cyber disaster.'
- TripleX is no opportunistic newcomer — just two months prior, the same group extracted 2TB from a major Indonesian state bank, signaling a disciplined, escalating campaign against large financial institutions.
- The combination of Aadhaar numbers with account details and login credentials creates complete identity profiles, giving bad actors direct pathways to impersonate customers, drain accounts, and commit fraud at scale.
- Bank of Baroda, CERT-In, and the Reserve Bank of India have all remained silent, leaving millions of customers without confirmation, instruction, or any institutional anchor in the face of potential identity theft.
In the quiet architecture of trust that holds modern banking together, a fracture has appeared: a hacking group called TripleX has allegedly placed over a terabyte of Bank of Baroda's most sensitive data onto the dark web, exposing the Aadhaar numbers, account credentials, and loan records of millions of Indians. The breach, surfacing on July 25th, strikes at the intersection of identity and finance — two systems that, in India, have been deliberately fused into one. As the bank and its regulators remain silent, the people most affected are left to navigate uncertainty alone, without warning, without guidance, and without recourse.
On July 25th, a cybersecurity tracking site flagged that over a terabyte of Bank of Baroda's most sensitive data had appeared on the dark web, allegedly posted there by a hacking group known as TripleX. The exposed material was sweeping in scope: savings and current accounts, loan records, NetBanking credentials, NRI and corporate division files, internal branch documents, and — most critically — Aadhaar numbers, the biometric identifiers that function as a master key to Indian identity and financial life.
Software engineer and CashlessConsumer founder Srikanth Lakshmanan was among the first to verify the breach, obtaining sample files from the leaked dataset and sharing them publicly. What he found went far beyond surface-level customer data — branch audits, loan appraisals, vigilance investigation records, and internal communications pointed to deep penetration of the bank's core systems. "It's a cyber disaster," he told India Today Tech.
TripleX is a relatively new but already consequential actor in the cybercriminal landscape. In May, the group breached PT Bank Negara Indonesia, one of that country's largest state-owned banks, extracting roughly 2TB of data. The pattern — targeting major financial institutions and releasing data publicly rather than holding it for ransom — suggests an organized operation with serious technical reach.
The stakes of this particular breach are amplified by what was taken. Aadhaar numbers paired with account details and login credentials form complete identity profiles, enabling fraud, impersonation, and unauthorized account access. The data is already in circulation on the dark web, free to download.
Yet as of the breach becoming public, Bank of Baroda had issued no statement. Neither CERT-In nor the Reserve Bank of India had confirmed or commented on the incident, leaving millions of customers in a vacuum — uncertain whether they were affected, what they should do, and whether anyone in authority was acting on their behalf. The silence, in its own way, compounds the damage the breach has already done.
On Saturday, July 25th, a cybersecurity tracking site flagged something alarming: over a terabyte of Bank of Baroda's most sensitive information had surfaced on the dark web, allegedly placed there by a hacking group called TripleX. The data dump included savings accounts, current accounts, loan records, NetBanking credentials, details from the bank's NRI and corporate divisions, and internal documents spanning multiple branches across India. Among the exposed material were Aadhaar numbers—the unique biometric identifier that serves as a master key to Indian identity and financial systems.
Srikanth Lakshmanan, a software engineer and founder of CashlessConsumer, was among the first to verify the breach's authenticity. He obtained sample documents from the leaked dataset and shared them publicly on X, confirming the link was live. When he examined the files, he found branch audits, loan appraisal documents, internal communications, vigilance investigation records, and customer application forms. "It's a cyber disaster," he told India Today Tech. The sheer volume and specificity of what had been stolen suggested not a surface-level hack but deep penetration into the bank's core systems.
TripleX, the group believed responsible, is relatively new to the cybercriminal landscape but already has a significant track record. In May of this year, the same group breached PT Bank Negara Indonesia, one of the country's largest state-owned banks, making off with approximately 2TB of data that included contracts, personal identification documents, financial transaction histories, and internal banking records. The pattern suggests an organized operation with the technical sophistication to target major financial institutions and the audacity to release stolen data publicly rather than hold it for ransom.
What makes this breach particularly consequential is the nature of what was exposed. Aadhaar numbers, when combined with account details and personal information, create a complete identity profile that can be weaponized for fraud, unauthorized transactions, and impersonation. The inclusion of NetBanking credentials means attackers potentially have direct access pathways into customer accounts. Loan data and internal documents reveal not just individual vulnerability but structural information about how the bank operates.
As of the time this breach became public, Bank of Baroda had offered no statement. Neither CERT-In, India's nodal agency for cybersecurity incidents, nor the Reserve Bank of India had confirmed or commented on the incident. This silence left millions of customers in a state of uncertainty—unable to know whether their information had been compromised, what steps they should take, or what the bank was doing in response.
The timing of this attack reflects a broader anxiety in India's financial sector. Cybersecurity threats have been escalating, with AI-powered attack capabilities drawing global concern. Earlier, in September 2025, the security firm UpGuard had discovered an exposed cloud database containing over 273,000 Indian banking records, of which 6,000 were linked to Bank of Baroda—though that incident involved a third-party system rather than the bank's own infrastructure. This latest breach, if confirmed, would represent a far more direct and damaging compromise of the institution itself.
The question now is whether Bank of Baroda and Indian regulators will move quickly to contain the damage, notify affected customers, and investigate how TripleX penetrated systems that should have been among the most heavily defended in the country. The data is already in the wild, free for download on the dark web. The window for preventing misuse has already closed.
Citações Notáveis
It's a cyber disaster.— Srikanth Lakshmanan, software engineer and founder of CashlessConsumer, after verifying the breach