Extortion group Triple X claims 1TB data leak from India's Bank of Baroda (2026)
An extortion crew calling itself Triple X listed India's state-owned Bank of Baroda on its dark-web site, claiming to have stolen about 1TB of customer and internal data.
- Victim
- Bank of Baroda
On 24 July 2026, a financially motivated extortion group calling itself Triple X listed Bank of Baroda โ one of India's largest state-owned banks โ on its dark-web leak site, claiming to have exfiltrated roughly 1 terabyte of data. The listing thrust one of India's systemically important lenders into a public extortion dispute over the scope and sensitivity of the material allegedly taken.
What was claimed
According to the group's postings and subsequent reporting, the dataset purportedly included customer KYC (know-your-customer) forms, Aadhaar and PAN identifiers, phone numbers, loan applications, non-resident Indian (NRI) banking records, corporate banking records, and internal branch audit reports drawn from multiple branches across India. If accurate, the combination of national identity numbers with financial account details would be especially damaging, giving fraudsters the raw material for identity theft and account takeover.
The bank's response
On 27 July 2026, Bank of Baroda confirmed that an employee's email account had been compromised and that unauthorised access to certain internal files had taken place. The bank maintained that its core banking infrastructure was never touched and that customer funds were not at risk. Reporting on the incident attributed the initial foothold to an ordinary weakness โ a weak password on one of the bank's systems โ rather than a sophisticated exploit.
Why it matters
Triple X, first observed in mid-2026 and focused on the financial and legal sectors, follows the now-familiar "name-and-shame" extortion playbook: publish a claim, apply reputational pressure, and negotiate. For a state-owned bank the size of Bank of Baroda, even an unverified 1TB claim carries regulatory and reputational weight, and the episode is a reminder that a single compromised mailbox โ reached through a weak password โ can open a path to sensitive internal data at an institution of national importance.
Timeline
The extortion group Triple X lists Bank of Baroda on its dark-web leak site, claiming roughly 1TB of stolen data.
Bank of Baroda confirms that an employee's email account was compromised and that unauthorised access to certain internal files occurred, while maintaining that core banking systems were not touched.
Sources
- deccanherald.comhttps://www.deccanherald.com/technology/data-breach-in-bank-of-baroda-1tb-of-customer-details-aadhaar-phone-numbers-leaked-on-darknet-4088773
- finance.yahoo.comhttps://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- gurucul.comhttps://gurucul.com/blog/bank-of-baroda-data-leak-analysis-of-the-triple-x-extortion-claim-and-exposed-customer-data/
- galaxywarden.comhttps://www.galaxywarden.com/blog/breach/bank-of-baroda-triple-x-2026-07