The material is said to contain customer and corporate
banking information, including Aadhaar numbers, names and loan records drawn
from several branches across India.
Software engineer and Cashless Consumer founder Srikanth
Lakshmanan posted those samples on X and said the link was active.
He said, "It's a cyber disaster."
The threat actor says the exposed dataset contains savings
and current account information, loan records, Net Banking user details, NRI
and corporate banking service records, customer support material, and records
related to branches or ATMs.
Lakshmanan said the issue was first noticed on dark web
tracking site www.ransomware.live
He said the information made public appears to include both
internal Bank of Baroda records and customer-related material.
"I was able to initially verify the documents and have
found a range of internal documents of the bank," he said.
"This includes branch audits, loan appraisal documents,
internal communications, vigilance investigations, bob World audit reports,
customer data including application forms across multiple BoB branches across
the country."
The Triple X ransomware group claimed to have exfiltrated 1
TB of data from India’s second-largest public sector bank. The full dump is
publicly accessible, with over 92,000 files observed across 9783
directories, including customer KYC, security reports, and internal audit
documents.
The data comes from what appears to be Bank of Baroda’s
internal SharePoint / file-sharing system not directly from the core banking
database (Finacle), but enough to cause serious harm.


