Bank of Baroda is facing serious cyber-security allegations after reports claimed that nearly 1TB of customer and internal data was dumped on the dark web. The alleged leak is said to include account details, Aadhaar information, loan papers and other sensitive records, though the bank has not publicly confirmed any breach so far.
What the leak claim says:
According to the reports, the dataset was first flagged by cybersecurity researcher Srikanth Lakshmanan, founder of CashlessConsumer, who said the material appeared to have surfaced on a dark web site over the weekend. The claim suggests that the exposed data may include customer application forms, identity documents, internal audit records, loan-related files, account statements, and NetBanking information.
Some reports say the alleged cache is larger than 700GB, while others put it at roughly 1TB, or 1,000GB. The variations appear to come from different ways of measuring the material found online, but the central concern remains the same: a large volume of banking data appears to have been made accessible outside the bank’s systems.
What information may be exposed:
The claim is especially worrying because the alleged leak is not limited to routine contact details. Reports say the material may include Aadhaar numbers, PAN-linked application records, savings and current account details, loan application forms, NRI and corporate banking documents, and even handwritten account-opening forms.
One report said the dark web listing included between 100,000 and 300,000 customer application forms, many with photographs and identity documents. Another said sample files also appeared to include branch audit reports, Bob World-related records and internal system folders. If the data is authentic, it could create a broad privacy and fraud risk for affected customers.
Bank and regulator response:
As of the latest reports, Bank of Baroda has not issued a public confirmation that a breach took place. The Reserve Bank of India and CERT-In have also not confirmed the incident, and there is no official word yet on whether the alleged leak came from a compromised email system, internal file share or some other entry point.
The absence of confirmation does not reduce the seriousness of the claim. In cases like this, banks usually have to verify whether the material is genuine, how it was obtained, and whether any customers or employees were directly impacted. Reports say a forensic audit may be needed to determine the source and scale of the exposure.
What customers should do now:
Even before the facts are fully confirmed, cybersecurity researchers are urging customers to stay alert for phishing attempts and suspicious account activity. Srikanth Lakshmanan reportedly advised users to change passwords across digital banking apps, monitor transaction alerts, block and reissue cards if needed, and lock Aadhaar biometrics through the UIDAI portal.
“Bank of Baroda data appears to be on the dark web; customers should change passwords and watch for phishing attempts.”~Srikanth Lakshmanan
“About 1TB of Bank of Baroda-related data is being claimed on the dark web, including savings, loan and NetBanking records.”~Dark Web Intelligence
“Bank of Baroda has reportedly been hacked and customer-linked files are circulating on the dark web.”~The Left Shift
“Bank of Baroda customers’ personal data and internal bank documents have allegedly leaked on the dark web.”~Dainik Bhaskar
For customers, the immediate risk may be less about direct account theft and more about follow-up scams, identity misuse and targeted fraud. Until the bank or regulators issue a formal update, the safest step is to tighten account security and stay watchful.




