Bank of Baroda data leak: If you are BoB account holder, don't worry, here are 5 things you must know
Bank of Baroda has been hacked, and data of thousands if not lakhs of customers is now available online for free. But if you are a Bank of Baroda customer, don't worry, here are 5 things that you should know about this data breach.
by Armaan Agarwal · India TodayIn Short
- Bank said an employee email compromise led to unauthorised data access
- Core banking systems stayed secure, while internal files appear exposed online
- Customers can use IFSC-based branch checker or contact branches directly
One of India’s largest public sector banks, Bank of Baroda, has been hacked. Over 1TB of sensitive customer data is now available online for anyone to access for free. But if you are a Bank of Baroda customer, you do not need to panic just yet. Here are 5 things that you should know about this data breach, and what you can do to keep your account secure.
To give you some context on the data breach, the hackers have put the data on the dark web. This data is said to include personal information such as account details, names, Aadhaar numbers, as well as loan approvals, internal audits and more. That is, anyone can now access this data dump and go through all this information.
Bank of Baroda has issued a statement regarding the breach. The bank says that the “incident involved compromise of an employee's email account, resulting in unauthorised access to certain data.” Though the bank added that its “core banking systems were not accessed and continue to remain secure.”
But does this mean that you should not use your Bank of Baroda account? Not really, let us go through everything you need to know.
1. Is my bank account at risk?
If you are worried that it may not be safe to use your Bank of Baroda account after the breach, software engineer Srikanth Lakshmanan says that the system that manages transactions likely was not impacted. “The bank's transactional system doesn't appear to be affected, but its internal file sharing seems to have been compromised,” he tells India Today Tech.
That is, while customer identity documents, bank statements, loan documents stored in these systems are said to be exposed, you can still continue making transactions normally.”
Subir Sangal, CEO of Eagle Information Systems says that there is a chance that a scammer may be able to access your account. Subir tells India Today Tech, “If there is leaked information which can be used to verify identity and/or account recovery, then there is a risk of unauthorised access. For precaution, it is advisable to change the password immediately, turn on multi factor authentication if available and keep an eye on account activity."
While details of Bank of Baroda accounts have been exposed, the scope of the breach remains unclear. That is, we don’t know how many, if not all accounts were exposed. Additionally, from what we have seen about the leak so far, it seems that only customer details or audit information was made available online, while passwords or PINs were likely not.
The one-time password, or OTP, system also remains in place. So, a hacker or someone using this information will still not be able to use your account without the OTP that comes to your mobile number. However, we would advise you to change passwords and PINs to be on the safer side.
2. Is there a way to check if my details were leaked?
The leaked information has been put up on the dark web. But this comes with two problems. First, to access the dark web, you need to use tor, or the onion router. And you will have to manually search for your information in a massive set of data.
But there is an easier way. Srikanth Lakshmanan’s CashlessConsumer has created a branch checker for this leak. He explains, “Customers can check using IFSC code if their branch is among 1088 (branches) that have been identified as likely exposed. Notification at individual level is not possible, something the bank should do.”
Subir Sangal concurs. He advises customers to contact their branch to find out details. “The responsibility of the bank is to investigate the incident, identify the affected customer(s) and advise them. It's best to reach out to the bank to clarify and follow all official correspondence,” Subir adds.
There are other services too. Cybersecurity expert and miniOrange CEO Anirban Mukherji tells India Today Tech, "Many services let you check if an email or phone number appeared in known breaches. Beyond that, checking your bank or credit card statements for unfamiliar transactions and reviewing your credit report are good habits."
3. What can someone do with my leaked data?
You may have one question in mind regarding this leak – how does this actually affect me? You see, screenshots from the leak shared online by Srikanth Lakshmanan, show details of account holders. This includes name, phone numbers, address, Aadhaar numbers, and more.
This means that identity theft could be easier. Someone could use these details to impersonate you, and potentially open bank accounts, or try to fake KYC submissions. Subir explains, “With enough personal and banking data leaked, cybercriminals can employ these stolen details in account takeover attacks, highly targeted phishing attacks, financial fraud or identity theft.”
Usually, scammers send phishing emails to many people at once, and hope that some fall for it. But when they have personal details available, they can make the message more credible. An email that addresses you by your actual name, instead of “Dear customer,” for instance, may be more convincing.
Phishing emails generally try to trick people into clicking malicious links, or sharing OTPs. So, you may have to be more vigilant now.
4. Does the leaked data compromise more than my bank account?
It is 2026, and almost everything is connected digitally today. This means that data of one thing being leaked online can have major ramifications across different things. And the same may be the case with the Bank of Baroda data breach.
Once someone gets access to your Aadhaar number, they may be able to find your sensitive information, not limited to your bank account – think government schemes, PF accounts, and more. A person may even impersonate you to try and scam your friends and family.
“Any personal information like your name, mobile no, email address, aadhaar details etc. which is exposed can have an impact beyond banking,” Subir Sangal says. “This data can be exploited by cybercriminals to attack your social media, shopping, e-wallet or other online accounts.”
You may want to be particularly cautious if you use the same password in multiple places. Anirban explains, "A leak tied to one account can become a stepping stone into email, social media, or other financial accounts if credentials or patterns are reused."
Beyond your personal data, the breach may also pose a major threat to Bank of Baroda’s operations. Srikanth notes, “The breach exposes large amounts of internal operational data of the bank and could be detrimental to general security of systems/processes in the bank.” Though the bank has confirmed that its core systems were never accessed.
5. What can I do to keep my account safe?
We have gone through everything that has happened, and what the potential risks are, but what can you as an account holder do? You see there is a saying for the internet, “Once it’s out there, it’s out there.” Now that this data is up, it's very hard to contain. Even if the original source is taken down, copies of this Bank of Baroda breach may spread through other online forums, or on the dark web.
This means that going forward, you need to be more careful. Like we said earlier, you should change your Bank of Baroda passwords across netbanking and mobile apps, as well as your PINs.
Srikanth adds that you must be more vigilant when it comes to talking to anyone about your account. “Enable and review transaction alerts carefully and be extremely cautious when speaking to anyone claiming to be a bank representative,” he says.
You may also want to keep track of your credit history, and see whether someone has tried to take out a loan in your name. While it is unlikely that someone will actually be able to use your details to do anything more than send you fraudulent emails, it is better to be safe than sorry.
- Ends