Synopsis : State-run Bank of Baroda (BoB) is investigating an alleged cyberattack after reports claimed that nearly 1 terabyte of sensitive banking data had been leaked on the dark web. The incident has once again highlighted the growing cybersecurity risks facing Indian companies and financial institutions. Over the past few years, several major organisations, including Tata Electronics, BSNL, WazirX, Air India and MobiKwik, have suffered large-scale cyberattacks that exposed millions of customer records and confidential business information.
Bank of Baroda has launched a comprehensive forensic investigation following reports that nearly 1 TB of confidential data has allegedly been leaked on the dark web. According to reports, the compromised information includes customer account details, retail and corporate banking records, loan information, internet banking records, NRI banking data, ATM-related information and branch details.
The Mumbai-headquartered public sector lender said it is working closely with regulatory authorities and cybersecurity experts to determine the source and extent of the breach. The bank has also initiated a detailed forensic audit to assess whether any customer information has been compromised and to strengthen its security systems against future attacks.
Although the investigation is still underway, the alleged breach has raised fresh concerns about cybersecurity in India's rapidly expanding digital banking ecosystem. Banks today store enormous volumes of financial and personal information, making them attractive targets for cybercriminals seeking financial data or sensitive customer records.
The latest incident is part of a growing list of major cyberattacks that have affected Indian companies across banking, healthcare, telecom, aviation, cryptocurrency and consumer technology sectors over the past few years. As businesses increasingly digitise their operations, cyberattacks have become more sophisticated, causing financial losses, operational disruptions and reputational damage.
One of the biggest cybersecurity incidents in recent months involved Tata Electronics. In June 2026, ransomware group World Leaks claimed responsibility for stealing more than 200,000 confidential files, amounting to over 630 GB of company data. Reports suggested that the leaked information included engineering documents, supplier information, manufacturing specifications and confidential files linked to Apple and Tesla. Some reports also claimed photographs of Apple's unreleased iPhone 18 Pro were among the leaked files, although the full extent of the breach remains under investigation.
Another significant breach involved Bharat Sanchar Nigam Limited (BSNL) in 2024. A hacker allegedly gained access to around 278 GB of internal company data before offering it for sale on a cybercrime forum. The Indian Computer Emergency Response Team (CERT-In) later confirmed that a possible intrusion had occurred. The leaked information reportedly contained subscriber records, SIM card details, International Mobile Subscriber Identity (IMSI) data, Home Location Register (HLR) information and network security details, raising concerns about the security of India's telecom infrastructure.
India's cryptocurrency sector also witnessed one of its largest cyberattacks when WazirX lost more than $230 million worth of digital assets in 2024. The attack targeted one of the exchange's multi-signature wallets, with investigators believing that attackers manipulated transaction data to gain control of the wallet. The incident forced WazirX to temporarily suspend cryptocurrency and rupee withdrawals while launching a detailed investigation. The stolen assets represented nearly half of the exchange's reserves, making it one of India's biggest crypto thefts.
Consumer electronics brand boAt also faced a major cybersecurity scare during 2024 after a hacker claimed to have leaked the personal information of over 7.5 million customers on the dark web. The leaked database reportedly included names, email addresses, phone numbers, residential addresses and customer identification details. Although the company launched an internal investigation and assured customers that data protection remained a priority, the incident highlighted the risks faced by consumer-facing digital businesses.
Perhaps one of India's largest alleged data breaches involved the Indian Council of Medical Research (ICMR) in 2023. Reports claimed that personal information belonging to more than 815 million Indians was being offered for sale online. The leaked dataset allegedly contained Aadhaar numbers, passport details, phone numbers and residential addresses. The massive breach triggered a multi-agency investigation, with Delhi Police later arresting four individuals in connection with the case.
The aviation sector also experienced a major cyberattack when Air India disclosed in 2021 that personal data of approximately 4.5 million passengers worldwide had been compromised. The exposed information included passenger names, passport details, ticket records, frequent flyer information and limited payment card details stored over nearly a decade. Air India clarified that sensitive card verification values (CVV) were not stored on the affected servers, reducing the potential financial impact for customers.
Digital payments platform MobiKwik also came under intense scrutiny in 2021 following reports that the personal information of nearly 110 million users had been leaked online. The alleged database included Know Your Customer (KYC) documents, phone numbers, email addresses and payment card information. While the company denied that its systems had been breached, the Reserve Bank of India directed it to conduct a detailed investigation and warned of regulatory action if security lapses were identified.
Cybersecurity experts note that ransomware attacks, phishing campaigns, credential theft and supply chain attacks have become increasingly common as businesses move more operations online. Financial institutions, telecom operators, healthcare organisations and technology companies remain among the most targeted sectors because they handle vast amounts of valuable customer information and critical infrastructure.
The latest Bank of Baroda investigation serves as another reminder that cybersecurity has become a strategic priority for both public and private organisations. As India's digital economy continues to expand rapidly through online banking, UPI payments, cloud computing and artificial intelligence, companies are expected to invest significantly more in advanced threat detection, encryption technologies, employee awareness programmes and real-time monitoring systems to protect customer data from increasingly sophisticated cyber threats.
Disclaimer : This content is intended solely for informational and educational purposes. It should not be considered financial, investment, business or legal advice. Readers and investors should conduct their own research and refer to official company announcements before making any financial or investment decisions.

