The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.
No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
On July 24, 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB of data from India's second-largest public sector bank. The full dump is publicly accessible on Tor with over 92,000 files observed — including customer KYC, security reports, and internal audit documents. These are indicative numbers from initial ongoing analysis.
📋 Understand the Breach 🔍 Check Your BranchComplete breakdown: what happened, what data was exposed, who did it, timeline, and consumer protection guide.
Read the full investigation →A super simple explanation of the breach in 10 languages. No jargon. Just the facts in plain language.
Read the simplified version →Search 9,992+ IFSC codes to see if your Bank of Baroda branch had data exposed. Search by IFSC, branch name, or city.
Check now →Our demands for regulatory action, customer notification, transparency, and accountability after this breach.
View demands →Methodology, LLM disclosure, how this research was conducted, and how CashlessConsumer approaches DPI investigations.
Learn more →What to do if you're a BoB customer: immediate steps to protect yourself, who to contact, and what to watch out for.
Protect yourself →