Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Bank of Baroda, one of India’s largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and publication of sensitive banking data. The bank disclosed that an employee’s email account was compromised, allowing unauthorized access to “certain data.” However, it confirmed that its core banking systems were not accessed or affected, and an investigation is currently underway. This incident highlights ongoing vulnerabilities within major financial institutions in Asia.

Details of the Incident

According to reports from cybersecurity researchers monitoring dark web activity, an unidentified hacker has allegedly breached Bank of Baroda and leaked what is claimed to be customer information, corporate banking records, internal emails, loan documents, and audit files on a darknet forum. The authenticity of this leaked data has not been independently verified, and Bank of Baroda has not commented on whether any customer data was exfiltrated or attributed the incident to a specific hacking group.

Threat Actor and Dark Web Activity

The threat actor, known as “leak-king-F,” has reportedly advertised the stolen data for sale on a popular darknet marketplace, directing potential buyers to a Telegram channel. This incident is part of a broader trend of cyber incidents affecting financial institutions across Asia, raising concerns about data security and the potential for further breaches.

Context of Recent Cyber Incidents

This incident follows other significant breaches in the region. Last week, Thailand’s Securities and Exchange Commission initiated an investigation into a data breach at the Thailand Securities Depository (TSD), where hackers claimed to have stolen investor information. Similarly, earlier this month, the ransomware group World Leaks published thousands of files allegedly stolen from contractors involved in India’s largest nuclear power project, although the state-owned nuclear operator stated that the documents did not affect safety or security.

As investigations continue, the situation remains fluid, and the implications for Bank of Baroda and its customers are still being assessed. For further details, refer to the report by The Record.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Supply Chain Attacks Target Developer Tools and CI/CD Pipelines, Research Reveals

In recent years, supply chain attacks have evolved dramatically, shifting from targeting finished software to infiltrating the very tools and code that developers use...

NordVPN Alerts Android Users to Malware Posing as Ryanair, Emirates, and Qatar Airways Apps

NordVPN has issued a warning to Android users about a sophisticated malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar...

AliExpress Exposed for Using Inaudible Sounds to Fingerprint Browser Visitors

AliExpress has come under scrutiny for employing an outdated method of browser fingerprinting that utilizes inaudible sounds to track visitors. This technique, which exploits...

ReliaQuest Confirms Targeting by ShinyHunters in Limited Social Engineering Attack

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest...