Skip to content
Data breachOngoing

Extortion group Triple X claims 1TB data leak from India's Bank of Baroda (2026)

An extortion crew calling itself Triple X listed India's state-owned Bank of Baroda on its dark-web site, claiming to have stolen about 1TB of customer and internal data.

Victim
Bank of Baroda

On 24 July 2026, a financially motivated extortion group calling itself Triple X listed Bank of Baroda โ€” one of India's largest state-owned banks โ€” on its dark-web leak site, claiming to have exfiltrated roughly 1 terabyte of data. The listing thrust one of India's systemically important lenders into a public extortion dispute over the scope and sensitivity of the material allegedly taken.

What was claimed

According to the group's postings and subsequent reporting, the dataset purportedly included customer KYC (know-your-customer) forms, Aadhaar and PAN identifiers, phone numbers, loan applications, non-resident Indian (NRI) banking records, corporate banking records, and internal branch audit reports drawn from multiple branches across India. If accurate, the combination of national identity numbers with financial account details would be especially damaging, giving fraudsters the raw material for identity theft and account takeover.

The bank's response

On 27 July 2026, Bank of Baroda confirmed that an employee's email account had been compromised and that unauthorised access to certain internal files had taken place. The bank maintained that its core banking infrastructure was never touched and that customer funds were not at risk. Reporting on the incident attributed the initial foothold to an ordinary weakness โ€” a weak password on one of the bank's systems โ€” rather than a sophisticated exploit.

Why it matters

Triple X, first observed in mid-2026 and focused on the financial and legal sectors, follows the now-familiar "name-and-shame" extortion playbook: publish a claim, apply reputational pressure, and negotiate. For a state-owned bank the size of Bank of Baroda, even an unverified 1TB claim carries regulatory and reputational weight, and the episode is a reminder that a single compromised mailbox โ€” reached through a weak password โ€” can open a path to sensitive internal data at an institution of national importance.

Timeline

  1. The extortion group Triple X lists Bank of Baroda on its dark-web leak site, claiming roughly 1TB of stolen data.

  2. Bank of Baroda confirms that an employee's email account was compromised and that unauthorised access to certain internal files occurred, while maintaining that core banking systems were not touched.

Sources

  1. deccanherald.comhttps://www.deccanherald.com/technology/data-breach-in-bank-of-baroda-1tb-of-customer-details-aadhaar-phone-numbers-leaked-on-darknet-4088773
  2. finance.yahoo.comhttps://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
  3. gurucul.comhttps://gurucul.com/blog/bank-of-baroda-data-leak-analysis-of-the-triple-x-extortion-claim-and-exposed-customer-data/
  4. galaxywarden.comhttps://www.galaxywarden.com/blog/breach/bank-of-baroda-triple-x-2026-07

Related incidents

Data breachdisputed

MobiKwik data breach

An 8.2TB trove tied to Indian fintech MobiKwik โ€” reportedly covering up to 99 million users with KYC documents, Aadhaar and card details โ€” was advertised for sale on a dark-web forum, in a breach the company repeatedly denied.

Victim
MobiKwik
Records
99.0M