Banking News

Read the full story

Source: The Hindu BusinessLine

The Hindu BusinessLine
Source
Banking Sector
Category
2 min
Read time
27 Jul
Published
Banking Sector
2 min read· The Hindu BusinessLine

Customer data from Bank of Baroda leaked online

A major public sector bank has reported a significant data security breach involving customer information. Bank officials are now investigating how sensitive internal documents ended up on the dark web.

Bank of Baroda (BoB) is currently dealing with a major security issue. Reports have surfaced that customer data and sensitive internal documents were leaked on the dark web (a hidden part of the internet used for illegal activities). The bank confirmed the incident on Monday and has already started a forensic investigation (a detailed technical search to find how a hack happened) to understand the full extent of the damage.

The breach reportedly happened because an employee's email account was compromised. This allowed hackers to gain unauthorised access to certain files. However, there is some relief for the bank as they stated that the Core Banking System (CBS) remains safe. The CBS is the heart of the bank that handles all transactions and account balances, so its safety means that money and daily operations are likely not directly affected.

According to cybersecurity researcher Srikanth L from Cashless Consumer, the leaked data is quite sensitive. It includes customer identification documents (like Aadhaar or PAN cards), loan papers, and internal audit records. These records help the bank check if rules are being followed, so their exposure is a serious matter. The data was discovered on a dark web site on Saturday night and is estimated to be around 700 gigabytes in size.

At this moment, it is not clear exactly how many customers have been affected by this leak. The bank has implemented containment measures to stop more data from being stolen. They are also working with relevant authorities, which usually include the Reserve Bank of India (RBI) and CERT-In (the government agency that handles cyber threats). This incident follows other recent cyberattacks on large Indian companies like Tata Electronics.

For bank officers, this news is a wake-up call about 'Insider Risk.' Even if the bank spends crores on security software, one compromised staff email can open the door for hackers. It highlights the importance of keeping passwords strong and being careful with phishing emails. If internal audit documents are leaked, it can also harm the bank’s reputation and trust with its clients.

For customers, such leaks increase the risk of identity theft. Scammers might use the leaked loan papers or ID digits to call customers and trick them. Bankers should be ready to answer questions from worried account holders about their data safety. It is important to remind everyone that bank staff will never ask for OTPs or passwords over the phone.

Looking ahead, the RBI is expected to keep a very close eye on how Bank of Baroda handles this recovery. The bank will need to strengthen its email security and monitor for any misuse of the leaked information. All banking aspirants should note that cybersecurity is now a top priority for the banking sector, as digital data is just as valuable as physical cash.

Source: The Hindu BusinessLine