India’s Bank of Baroda confirms cyber incident after hackers claim data theft
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.
One of India's largest state-owned banks has reported a cybersecurity incident after a threat actor claimed to have stolen and published sensitive banking data.
Bank of Baroda said Monday that an employee's email account had been compromised, allowing unauthorized access to "certain data." The bank said it detected and contained the incident immediately and that its core banking systems were not accessed or affected. An investigation is ongoing.
The disclosure follows claims last week by multiple cybersecurity researchers tracking dark web activity that an unidentified hacker had breached the bank and leaked what it described as customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum.
Source: https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
Related breach coverage
- Clover Health Investments Discloses Data Breach2026-07-21
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
- Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances2026-07-20
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks […]
- Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials2026-07-26
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel […]
- AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads2026-07-15
AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packages that together account for over 2 million weekly downloads. The affected versions are @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1, […]
