Desk live·
ForensicPost
Breaches/Verification/File 26-0807

Bank of Baroda Confirms Leak After Employee Email Compromise, With 700GB Claimed

One compromised employee email account at Bank of Baroda. The dataset advertised on a criminal forum is described as 700GB, with some claims of a terabyte; the bank says access was limited to certain data and core banking was untouched. Neither figure has been verified.

Constructed geometry · not a chart of case data
JurisdictionIndiaVadodarathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBank of Baroda
ActorUnattributed
D. Kennedy11 min readConfidence: medium3 sources reviewed

Bank of Baroda opened a forensic investigation after customer data and internal documents were advertised following the compromise of an employee email account. Metadata associated with the cache is reported as more than 700GB, with some claims putting it at a terabyte; the size has not been independently verified.

The bank confirmed a leak, said unauthorised access was limited to certain data, and stated that core banking systems remain secure with containment measures applied. Reported sample contents include customer names, photographs, Aadhaar details, account-opening forms and account information, with the wider set said to cover savings and current accounts, net banking users, non-resident customers, corporate services, branches and ATMs. Neither the Reserve Bank of India nor CERT-In had issued a public statement at the time of reporting.

Two Numbers, Neither Checkable

A volume figure of 700GB originates with the party advertising the material. A characterisation of "certain data" originates with the party that would prefer the number to be small. This desk can verify neither and prints both.

We filed the same standoff at 22-1104b, where an operation claimed 40TB and the company confirmed only that significant data was taken, and at 23-0715, where one volume figure was attributed to two different operations and the desk declined to carry it. Volume is the least reliable field in this database and the one most reliably reported as fact.

Aadhaar Is In The Samples

Whatever the total, the described contents include Aadhaar details — India’s national identity number, linked to biometric enrolment and used across banking, welfare and telecommunications.

We have recorded unresettable identifiers at 26-0726, at 22-0922 and at 24-0313, where a French national number encoding date and place of birth was exposed. The category question is not how many gigabytes moved but whether the fields inside can be reissued, and here the central one cannot. A dispute about volume is a dispute about the wrong axis.

One Mailbox

The stated entry is a single employee email account. Whatever the eventual figure, it passed through one person’s mailbox.

We keep arriving here — 22-0705, where one hotel associate’s machine gave up 20GB in six hours; 22-0825, where one developer account led to the December compromise at 22-1222. A mailbox at a large institution accumulates attachments nobody catalogued, and the corpus has no file in which an organisation could say what was in one before it was taken.

The Regulators Have Not Spoken

At the time of reporting neither the central bank nor the national CERT had commented publicly.

The desk records that as a state of the record rather than a criticism — investigations take time and silence during one is often correct. It matters because in the absence of a regulator, the only two accounts available are the attacker’s and the bank’s, which is exactly the condition this file is graded medium for.

How we reported this

Compiled from the bank’s public statements and contemporaneous reporting, listed below. The volume figures originate with the party advertising the data and are carried as claims, not findings; the bank’s characterisation is carried as a claim on the other side. This desk has not accessed any leaked material and no sample is described beyond category. No affected-individual count exists. Corrections: corrections@forensicpost.com.

Sources
  1. Bank of Baroda Confirms Data Leak After Employee Email Compromised; Maintains Core Banking System SafeETV Bharat
  2. Bank of Baroda Data Leak: Dark Web Breach, Customer Records Exposed and Cybersecurity Probe Under WayGulf News
  3. India’s Bank of Baroda data breach exposes customer records after employee email compromiseThe Asian Banker
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary