Bank of Baroda Admits Employee Email Breach After Ransomware Group Claims Massive Data Theft

Bank of Baroda has officially acknowledged a cybersecurity incident following reports that internal documents were leaked online. The Triple X ransomware group claimed responsibility, alleging they had exfiltrated 1 TB of data, including customer KYC information, security reports, and internal audit documents spanning over 92,000 files across nearly 10,000 directories.

In a statement posted on X (formerly Twitter), the bank said, “The Bank has robust information security protocols in place. The incident involved the compromise of an employee’s email account, resulting in unauthorised access to certain data.” Bank of Baroda emphasized that the breach was detected immediately and that necessary containment measures were taken. The core banking system, powered by Finacle, was not affected, and customer funds remain secure.

A forensic investigation is now underway to identify the perpetrators. The bank reiterated its commitment to “maintaining the highest standards of information security and to safeguarding the trust of its customers and stakeholders.”

While the breach appears limited to internal SharePoint and file-sharing systems, cybersecurity experts have expressed concern over the potential risks to affected individuals, particularly if sensitive KYC data is exposed.

Why Banks Remain a Prime Target for Cybercriminals

Financial institutions handle vast amounts of sensitive personal and financial data, making them attractive targets. Attackers often use phishing and social engineering to compromise employee accounts rather than attempting to breach core banking systems directly.

Banks employ multiple layers of defense, including encryption, multi-factor authentication, and regular security audits. Employee training on recognizing suspicious emails is also critical. Despite these measures, cyberattacks continue to escalate, forcing banks to constantly evolve their security posture.

Customers are advised never to share OTPs, PINs, passwords, or banking details over calls, messages, or emails. Regularly monitoring account statements and enabling transaction alerts can help detect unauthorized activity early. Any suspicious transactions should be reported to the bank immediately.

As the investigation continues, Bank of Baroda urges customers to remain vigilant and follow best practices for online security.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *