🤖
LLM-Enabled Investigation — Read This First.
The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.

No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
🔴 July 27, 2026 — Ongoing Investigation

Your Data Was in the BoB Breach.
Here's What We Found.

On July 24, 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB of data from India's second-largest public sector bank. The full dump is publicly accessible on Tor with over 92,000 files observed — including customer KYC, security reports, and internal audit documents. These are indicative numbers from initial ongoing analysis.

→ Understand the Breach 🔍 Check Your Branch
92K+
Files Observed
9,783
Directories
62
Top-Level Branches
1,088+
Branches Impacted
~1 TB
Data Volume
📋 What Happened 📂 Exposed Data 🕵️ Threat Actor 🏦 Affected Branches 🔍 IFSC Check 📅 Timeline 🛡️ Consumer Guide

📋 What Happened A plain-English explainer of the Bank of Baroda data breach

🔴 Bottom Line: If you're a Bank of Baroda customer, your personal information — including KYC documents, account details, and loan records — may have been exposed. Here's what you need to know.

What is this breach?

On July 24, 2026, a ransomware group called Triple X claimed to have broken into Bank of Baroda's internal systems and stolen massive amounts of data. The group published the stolen data on the dark web (Tor network) — completely accessible to anyone, with no password required.

The investigation by CashlessConsumer confirmed over 92,000 files across 9,783 directories are visible in the publicly available dump. The data comes from what appears to be Bank of Baroda's internal SharePoint / file-sharing system — not directly from the core banking database (Finacle), but enough to cause serious harm.

How did it happen?

According to Triple X's announcement, the breach was enabled by a "weak password". The attackers likely:

  1. Gained initial access through compromised credentials
  2. Moved laterally through Bank of Baroda's internal network
  3. Reached the SharePoint / file server infrastructure
  4. Exfiltrated ~1 TB of documents over an extended period
  5. Published everything publicly

What data was stolen?

The dump covers nearly every aspect of the bank's operations:

  • Customer KYC — eKYC dumps, CKYC lists, ReKYC notices (178 MB)
  • Legal & Audit Docs — Legal notices, audit reports, compliance docs (63 MB)
  • Loan Records — Gold loans, home loans, NPAs, IRAC data
  • VAPT Reports — Security vulnerability reports (iOS, Android, NEFT-RTGS)
  • Network Configs — httpd.conf (DC+DR), firewall rules, VPN configs
  • Employee Workspaces — Named employee directories with personal files
  • International Ops — UAE, Botswana, Fiji, Kenya, Guyana, Uganda branches
  • Transaction Data — IRAC loan dumps, reconciliation data, MAU transactions

Who is affected?

Virtually all Bank of Baroda customers are potentially affected. The compromised file server covered operations across 62 top-level branches including zones and regions spanning all of India and 12+ international locations. Customer data was found in KYC lists, transaction dumps, loan files, and audit documents — meaning if you've had any relationship with BoB, your data may be in the dump.

⚡ Important: The dump does NOT appear to include direct access to Finacle (core banking system), so account passwords and sensitive transaction credentials may not be directly exposed. However, the KYC data (Aadhaar, PAN, photos) and loan documents are sufficient for identity theft and social engineering attacks.

📂 What Data Was Exposed Indicative counts from initial ongoing analysis

🔴 Critical: Approximately 242 MB of high-signal files identified through directory listing analysis. ~4.1 GB more observed across the full dump. These are preliminary numbers from ongoing analysis.

Critical Evidence Identified in Dump

🔴 Legal & Audit Documents

Legal notices, customer confirmation documents, audit findings, and vendor correspondence are present in the dump. These expose internal legal processes and third-party contract details.

🔴 Customer PII (KYC)

Full eKYC dumps (53.8 MB), customer KYC lists (45.9 MB), ReKYC test data (35.8 MB), and DBT BSBD accounts due for ReKYC (26 MB). These contain Aadhaar numbers, PAN cards, photographs, and address proofs.

🔴 VAPT / Security Reports

Security vulnerability reports for Bob World mobile app (iOS 3.7.1/3.7.2, Android), Base24, BBPS API, NEFT-RTGS, and international banking platforms (Uganda, Guyana). This gives attackers a complete map of the bank's security weaknesses.

🔴 Infrastructure Configs

File names reveal Apache httpd.conf files (Data Center + Disaster Recovery), server configuration details, backup policies, SIEM integration logs, technical architecture manuals, and threat model documents. Network packet capture (PCAP) files also visible in directory listing.

File Types Breakdown

The most common file types in the dump:

PDF
13,678 files (86.7%)
XLSX/XLS
993 files
ZIP/7z
436 archives
JPG/PNG
601 images
APK/IPA
23 mobile binaries
DB/ACCDB
17 database files
PCAP
2 network captures
E codes, WSDL, CERT
5+ enterprise archives

🕵️ Threat Actor: Triple X Profile of the ransomware group behind the Bank of Baroda breach

⚡ Assessment: Triple X is a new, financially motivated criminal group with specialised skill in targeting large Asian banks. First observed May 2026. Only 2 confirmed victims (BNI Indonesia, BoB India) in ~2.5 months.

Group Profile

NameTriple X (TripleX, TX)
TypeRansomware-as-a-Service / Data extortion
First Seen~May 1-10, 2026
Leak SiteTor onion service (no auth)
VictimsBNI (Indonesia), Bank of Baroda (India)
Target SectorFinancial services (state-owned banks)
Geographic FocusAsia-Pacific (Indonesia, India)
M.O.Double extortion + public leak + full dump access

Modus Operandi

  1. Initial Access: Weak/compromised credentials (possibly VPN or RDP)
  2. Lateral Movement: Harvested Windows domain credentials, moved through SharePoint/file server infrastructure
  3. Exfiltration: ~1 TB of data using rclone or similar tool (detectable but not stopped)
  4. Encryption: Double extortion — encrypt victim data + threaten public release
  5. Leak: Full directory listing published on Tor — no paywall, no staged release

Known Attack Timeline

DateEvent
May 2026Triple X first observed / establishes leak infrastructure
May 11, 2026Claims breach of Bank Negara Indonesia (BNI) — ~2 TB data
June 2026Added to WatchGuard ransomware tracker as "data broker variant"
July 24, 2026Claims Bank of Baroda breach — ~1 TB, "weak password" attribution
July 25-26, 2026Full BoB dump publicly accessible on Tor — verified by CashlessConsumer

Attribution & Open Questions

Confidence: Low-to-Moderate. Triple X is very new with only 2 confirmed victims. No known ties to established ransomware families, state actors, or prior criminal groups.

Key unknowns: Is the "weak password" claim accurate? Does Triple X operate purely for profit or is there a geopolitical dimension? Are they a new independent group or a rebrand of an existing actor? What was the ransom demand?

🏦 Affected Branches & Regions 62 top-level branches with confirmed data exposure across 31 states/UTs

⚡ Scope: 248 cities across India and 12+ international locations have confirmed exposure. Every major BoB zone is represented: audits, KYC data, loan files, and confidential reports were found in the dump.

Browse branches by state to see the scale of the breach:

🔍 Check Your Branch — IFSC Search Search your branch's IFSC code to see if data was exposed

⚠️ How this works: We've cross-referenced 9,992 Bank of Baroda IFSC codes against over 92,000 files visible in the publicly available breach data. Branches with files found in the breach are marked ⚠️ EXPOSED. Branches not found may still be affected — the dump only covers what was on the compromised file server.
Tip: All BoB IFSCs start with BARB0. You can also search by city or branch name.

Understanding Your Risk Level

🔴 Critical (KYC/PII Exposed)
Your branch had KYC documents, customer lists, or identity records in the dump. Risk of identity theft and phishing is HIGH.

🟡 Medium (Audit/Operations)
Your branch appears in audit reports, operations documents, or internal data. Lower direct PII risk but exposure is confirmed.

⚪ No Data Found
No files from your branch were found in the dump. This could mean it wasn't on the compromised server — but remain vigilant.

❓ Not Searched
Enter an IFSC code or branch name above to check your branch's status.

📅 Breach Timeline From Triple X's emergence to full public disclosure — a chronological account

🛡️ Consumer Protection Guide What to do if you're a Bank of Baroda customer

🔴 Take action now. If you have an account with Bank of Baroda, assume your personal data has been exposed. Here's your action plan:

✅ Immediate Steps

  • Check your branch using the IFSC search above to see if your branch was in the dump
  • Enable transaction alerts on all BoB accounts — SMS and email for every debit/credit
  • Change your net banking password and enable 2-factor authentication
  • Update your bob World app PIN and ensure you're running the latest version
  • Review recent transactions for any unauthorised activity — report immediately if found
  • Freeze your credit report with credit bureaus (CIBIL, Experian, Equifax) to prevent new account fraud

📞 Who to Contact

  • Bank of Baroda Helpline
    1800 258 44 55 (toll-free)
    1800 1022 445 (toll-free)
  • RBI Banking Ombudsman
    https://cms.rbi.org.in — Register a complaint
  • Cyber Crime Portal
    https://cybercrime.gov.in — Report identity theft
  • File a Police Complaint
    Report identity theft and fraud at your local cyber crime police station
  • CashlessConsumer Investigation
    Follow updates at cashlessconsumer.in

⚠️ Watch Out For

🔴 Phishing Scams
Expect fake calls, SMS, and emails pretending to be from BoB offering "protection" or asking you to "verify" your account. The leaked KYC data gives scammers everything they need to sound legitimate.

🔴 Loan Fraud
With KYC documents and loan records exposed, fraudsters may attempt to open loans in your name. Monitor CIBIL score regularly.

🟡 SIM Swap Attacks
Personal details in the dump enable SIM swap attacks. Contact your mobile provider to add extra verification.

🟡 Social Engineering
Scammers may reference specific transaction details from the dump. Never share OTPs or passwords.

📢 What We're Doing