LLM-Enabled Investigation — Read This First.
The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.
No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
🔴 July 27, 2026 — Ongoing Investigation
Your Data Was in the BoB Breach. Here's What We Found.
On July 24, 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB of data from India's second-largest public sector bank. The full dump is publicly accessible on Tor with over 92,000 files observed — including customer KYC, security reports, and internal audit documents. These are indicative numbers from initial ongoing analysis.
📋 What Happened A plain-English explainer of the Bank of Baroda data breach
🔴 Bottom Line: If you're a Bank of Baroda customer, your personal information — including KYC documents, account details, and loan records — may have been exposed. Here's what you need to know.
What is this breach?
On July 24, 2026, a ransomware group called Triple X claimed to have broken into Bank of Baroda's internal systems and stolen massive amounts of data. The group published the stolen data on the dark web (Tor network) — completely accessible to anyone, with no password required.
The investigation by CashlessConsumer confirmed over 92,000 files across 9,783 directories are visible in the publicly available dump. The data comes from what appears to be Bank of Baroda's internal SharePoint / file-sharing system — not directly from the core banking database (Finacle), but enough to cause serious harm.
How did it happen?
According to Triple X's announcement, the breach was enabled by a "weak password". The attackers likely:
Gained initial access through compromised credentials
Moved laterally through Bank of Baroda's internal network
Reached the SharePoint / file server infrastructure
Exfiltrated ~1 TB of documents over an extended period
Published everything publicly
What data was stolen?
The dump covers nearly every aspect of the bank's operations:
Employee Workspaces — Named employee directories with personal files
International Ops — UAE, Botswana, Fiji, Kenya, Guyana, Uganda branches
Transaction Data — IRAC loan dumps, reconciliation data, MAU transactions
Who is affected?
Virtually all Bank of Baroda customers are potentially affected. The compromised file server covered operations across 62 top-level branches including zones and regions spanning all of India and 12+ international locations. Customer data was found in KYC lists, transaction dumps, loan files, and audit documents — meaning if you've had any relationship with BoB, your data may be in the dump.
⚡ Important: The dump does NOT appear to include direct access to Finacle (core banking system), so account passwords and sensitive transaction credentials may not be directly exposed. However, the KYC data (Aadhaar, PAN, photos) and loan documents are sufficient for identity theft and social engineering attacks.
📂 What Data Was Exposed Indicative counts from initial ongoing analysis
🔴 Critical: Approximately 242 MB of high-signal files identified through directory listing analysis. ~4.1 GB more observed across the full dump. These are preliminary numbers from ongoing analysis.
Critical Evidence Identified in Dump
🔴 Legal & Audit Documents
Legal notices, customer confirmation documents, audit findings, and vendor correspondence are present in the dump. These expose internal legal processes and third-party contract details.
🔴 Customer PII (KYC)
Full eKYC dumps (53.8 MB), customer KYC lists (45.9 MB), ReKYC test data (35.8 MB), and DBT BSBD accounts due for ReKYC (26 MB). These contain Aadhaar numbers, PAN cards, photographs, and address proofs.
🔴 VAPT / Security Reports
Security vulnerability reports for Bob World mobile app (iOS 3.7.1/3.7.2, Android), Base24, BBPS API, NEFT-RTGS, and international banking platforms (Uganda, Guyana). This gives attackers a complete map of the bank's security weaknesses.
🔴 Infrastructure Configs
File names reveal Apache httpd.conf files (Data Center + Disaster Recovery), server configuration details, backup policies, SIEM integration logs, technical architecture manuals, and threat model documents. Network packet capture (PCAP) files also visible in directory listing.
File Types Breakdown
The most common file types in the dump:
PDF 13,678 files (86.7%)
XLSX/XLS 993 files
ZIP/7z 436 archives
JPG/PNG 601 images
APK/IPA 23 mobile binaries
DB/ACCDB 17 database files
PCAP 2 network captures
E codes, WSDL, CERT 5+ enterprise archives
🕵️ Threat Actor: Triple X Profile of the ransomware group behind the Bank of Baroda breach
⚡ Assessment: Triple X is a new, financially motivated criminal group with specialised skill in targeting large Asian banks. First observed May 2026. Only 2 confirmed victims (BNI Indonesia, BoB India) in ~2.5 months.
Group Profile
Name
Triple X (TripleX, TX)
Type
Ransomware-as-a-Service / Data extortion
First Seen
~May 1-10, 2026
Leak Site
Tor onion service (no auth)
Victims
BNI (Indonesia), Bank of Baroda (India)
Target Sector
Financial services (state-owned banks)
Geographic Focus
Asia-Pacific (Indonesia, India)
M.O.
Double extortion + public leak + full dump access
Modus Operandi
Initial Access: Weak/compromised credentials (possibly VPN or RDP)
Lateral Movement: Harvested Windows domain credentials, moved through SharePoint/file server infrastructure
Exfiltration: ~1 TB of data using rclone or similar tool (detectable but not stopped)
Encryption: Double extortion — encrypt victim data + threaten public release
Leak: Full directory listing published on Tor — no paywall, no staged release
Known Attack Timeline
Date
Event
May 2026
Triple X first observed / establishes leak infrastructure
May 11, 2026
Claims breach of Bank Negara Indonesia (BNI) — ~2 TB data
June 2026
Added to WatchGuard ransomware tracker as "data broker variant"
July 24, 2026
Claims Bank of Baroda breach — ~1 TB, "weak password" attribution
July 25-26, 2026
Full BoB dump publicly accessible on Tor — verified by CashlessConsumer
Attribution & Open Questions
Confidence: Low-to-Moderate. Triple X is very new with only 2 confirmed victims. No known ties to established ransomware families, state actors, or prior criminal groups.
Key unknowns: Is the "weak password" claim accurate? Does Triple X operate purely for profit or is there a geopolitical dimension? Are they a new independent group or a rebrand of an existing actor? What was the ransom demand?
🏦 Affected Branches & Regions 62 top-level branches with confirmed data exposure across 31 states/UTs
⚡ Scope:248 cities across India and 12+ international locations have confirmed exposure. Every major BoB zone is represented: audits, KYC data, loan files, and confidential reports were found in the dump.
Browse branches by state to see the scale of the breach:
🔍 Check Your Branch — IFSC Search Search your branch's IFSC code to see if data was exposed
⚠️ How this works: We've cross-referenced 9,992 Bank of Baroda IFSC codes against over 92,000 files visible in the publicly available breach data. Branches with files found in the breach are marked ⚠️ EXPOSED. Branches not found may still be affected — the dump only covers what was on the compromised file server.
Tip: All BoB IFSCs start with BARB0. You can also search by city or branch name.
Understanding Your Risk Level
🔴 Critical (KYC/PII Exposed) Your branch had KYC documents, customer lists, or identity records in the dump. Risk of identity theft and phishing is HIGH.
🟡 Medium (Audit/Operations) Your branch appears in audit reports, operations documents, or internal data. Lower direct PII risk but exposure is confirmed.
⚪ No Data Found No files from your branch were found in the dump. This could mean it wasn't on the compromised server — but remain vigilant.
❓ Not Searched Enter an IFSC code or branch name above to check your branch's status.
📅 Breach Timeline From Triple X's emergence to full public disclosure — a chronological account
🛡️ Consumer Protection Guide What to do if you're a Bank of Baroda customer
🔴 Take action now. If you have an account with Bank of Baroda, assume your personal data has been exposed. Here's your action plan:
✅ Immediate Steps
Check your branch using the IFSC search above to see if your branch was in the dump
Enable transaction alerts on all BoB accounts — SMS and email for every debit/credit
Change your net banking password and enable 2-factor authentication
Update your bob World app PIN and ensure you're running the latest version
Review recent transactions for any unauthorised activity — report immediately if found
Freeze your credit report with credit bureaus (CIBIL, Experian, Equifax) to prevent new account fraud
📞 Who to Contact
Bank of Baroda Helpline 1800 258 44 55 (toll-free) 1800 1022 445 (toll-free)
RBI Banking Ombudsman https://cms.rbi.org.in — Register a complaint
File a Police Complaint Report identity theft and fraud at your local cyber crime police station
CashlessConsumer Investigation Follow updates at cashlessconsumer.in
⚠️ Watch Out For
🔴 Phishing Scams Expect fake calls, SMS, and emails pretending to be from BoB offering "protection" or asking you to "verify" your account. The leaked KYC data gives scammers everything they need to sound legitimate.
🔴 Loan Fraud With KYC documents and loan records exposed, fraudsters may attempt to open loans in your name. Monitor CIBIL score regularly.
🟡 SIM Swap Attacks Personal details in the dump enable SIM swap attacks. Contact your mobile provider to add extra verification.
🟡 Social Engineering Scammers may reference specific transaction details from the dump. Never share OTPs or passwords.
📢 What We're Doing
Continuing to monitor the Tor dump server for new data dumps
Cataloging all exposed files to identify affected branches and customers
Liaising with cyber security researchers to track Triple X activity
Publishing updates as the situation develops
Advocating for regulatory action and improved breach notification protocols