State-run Bank of Baroda has confirmed that customer-related information was exposed after an employee’s email account was compromised in a cyber incident.
While the lender has assured customers that its core banking systems remain secure and banking operations continue as normal, the breach has raised concerns over the possible misuse of personal data.
The disclosure follows claims by cybersecurity researchers that more than 1TB of customer and internal banking data has surfaced online.
The full extent of the breach is still under investigation.
Bank of Baroda said the cyber incident was limited to an employee’s email account and did not affect its core banking infrastructure, which handles customer transactions.
The bank said normal banking services, including deposits, withdrawals and digital transactions, remain fully operational.
It also said it is investigating the incident and taking appropriate measures to strengthen its cybersecurity systems.
More from Business Bank of Baroda probes major leak of customer data and internal records after dark web exposure 'Release the traces': Hugging Face CEO makes two demands after OpenAI's rogue AI hacked its systems What information may have been leaked?
According to reports, the leaked data could include customer names, phone numbers, addresses, Aadhaar-related details, account information, loan documents and some internal banking records.
There is currently no indication that internet banking passwords, ATM PINs or one-time passwords (OTPs) were compromised.
Even so, cybersecurity experts warn that personal information alone can be valuable to cybercriminals and may be used for identity theft or social engineering attacks.
Is it safe to continue using your account?
Yes.
Since the bank’s core banking systems were not affected, customers can continue using their Bank of Baroda accounts as usual.
However, experts recommend taking precautionary steps because fraudsters may use leaked personal information to impersonate bank officials or send convincing phishing emails, text messages or phone calls.
What should customers do now?
Customers are advised to change their internet banking and mobile banking passwords as a precaution.
Those who are concerned can also reset their ATM PINs and enable multi-factor authentication wherever available.
They should regularly monitor account statements and transaction alerts for any suspicious activity.
Any unauthorised transaction should be reported to the bank immediately.
Customers should also avoid responding to unsolicited calls, emails or SMS messages claiming to be from Bank of Baroda.
The bank has repeatedly reminded users never to share OTPs, PINs, passwords or CVV numbers with anyone.
Quick Reads View All Buying bottled water?
Here's what FSSAI's 'high-risk' tag really means for consumers RBI gets govt approval for polymer note trials: When will Rs 10 and Rs 20 plastic notes launch?
How can customers check if they were affected?
Bank of Baroda has not released a public list of affected customers.
Customers seeking confirmation can contact their home branch or the bank’s customer care for official information.
Cybersecurity researchers have also published online tools that reportedly allow users to check whether their branch is among those linked to the leaked data using the branch’s IFSC code.
Why the breach still matters Although the bank has maintained that its transaction systems remain secure, experts say data breaches can have long-term consequences.
Leaked personal information can be used to carry out targeted phishing campaigns, identity theft and financial fraud months after the original incident.
Bank of Baroda has said it is continuing its investigation while ensuring that normal banking services remain unaffected.