The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.
No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
BoBBreach is a consumer-focused investigation portal for the July 2026 Bank of Baroda data breach. Built and maintained by CashlessConsumer — a fintech and digital public infrastructure research initiative.
When the Triple X ransomware group published Bank of Baroda's stolen data on the open Tor network, affected customers had no way to understand what happened, whether their data was compromised, or what to do next. The bank's official communication was minimal.
BoBBreach was launched within 48 hours of the breach going public — to give consumers a clear, independent account of the breach, help them check if their branch was affected, and provide actionable steps to protect themselves.
Data source: Publicly accessible directory listing from the Triple X Tor leak server. We crawled only the directory structure and file metadata — no actual file contents were downloaded or analyzed.
Cross-referencing: File paths, names, and document types visible in the directory listing were programmatically extracted and cross-referenced against the Razorpay IFSC database (9,992 Bank of Baroda IFSC codes). This allowed us to map exposed files to specific branches, regions, and data categories.
Data classification: Files were categorised by type (KYC, audit, loan, VAPT, etc.) based on naming patterns in the directory structure — e.g., folders named "eKYC Sample", "CKYCR" and file names containing "ReKYC", "IRAC", etc.
CashlessConsumer is an independent fintech and digital public infrastructure (DPI) research initiative. We investigate, document, and explain how India's financial systems actually work — especially when they break.
This breach investigation is part of a broader body of work. For a deeper look at our research approach and other investigations:
🔪 Killer Loan Apps Investigation
Predatory digital lending apps, data harvesting, regulatory gaps, and Chinese entity links — a deep-dive into India's fintech dark side.
🏦 .bank.in Governance Report
IDRBT's domain security, procurement irregularities, unauthenticated APIs, and institutional accountability failures at India's banking technology regulator.
For a full overview of our research, visit cashlessconsumer.in — fintech analysis, DPI research, security audit findings, and daily market coverage.
Questions, corrections, or tips? Get in touch.
All content on this site is published for research and educational purposes. No personally identifiable information from the dump is distributed on this site. Raw metadata is retained for investigative purposes only.
Built independently. Not affiliated with Bank of Baroda, the Government of India, or any law enforcement agency.