The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.
No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
On July 24, 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB of data from India's second-largest public sector bank. The full dump is publicly accessible on Tor with over 92,000 files observed — including customer KYC, security reports, and internal audit documents. These are indicative numbers from initial ongoing analysis.
→ Understand the Breach 🔍 Check Your BranchOn July 24, 2026, a ransomware group called Triple X claimed to have broken into Bank of Baroda's internal systems and stolen massive amounts of data. The group published the stolen data on the dark web (Tor network) — completely accessible to anyone, with no password required.
The investigation by CashlessConsumer confirmed over 92,000 files across 9,783 directories are visible in the publicly available dump. The data comes from what appears to be Bank of Baroda's internal SharePoint / file-sharing system — not directly from the core banking database (Finacle), but enough to cause serious harm.
According to Triple X's announcement, the breach was enabled by a "weak password". The attackers likely:
The dump covers nearly every aspect of the bank's operations:
Virtually all Bank of Baroda customers are potentially affected. The compromised file server covered operations across 62 top-level branches including zones and regions spanning all of India and 12+ international locations. Customer data was found in KYC lists, transaction dumps, loan files, and audit documents — meaning if you've had any relationship with BoB, your data may be in the dump.
Legal notices, customer confirmation documents, audit findings, and vendor correspondence are present in the dump. These expose internal legal processes and third-party contract details.
Full eKYC dumps (53.8 MB), customer KYC lists (45.9 MB), ReKYC test data (35.8 MB), and DBT BSBD accounts due for ReKYC (26 MB). These contain Aadhaar numbers, PAN cards, photographs, and address proofs.
Security vulnerability reports for Bob World mobile app (iOS 3.7.1/3.7.2, Android), Base24, BBPS API, NEFT-RTGS, and international banking platforms (Uganda, Guyana). This gives attackers a complete map of the bank's security weaknesses.
File names reveal Apache httpd.conf files (Data Center + Disaster Recovery), server configuration details, backup policies, SIEM integration logs, technical architecture manuals, and threat model documents. Network packet capture (PCAP) files also visible in directory listing.
The most common file types in the dump:
| Name | Triple X (TripleX, TX) |
| Type | Ransomware-as-a-Service / Data extortion |
| First Seen | ~May 1-10, 2026 |
| Leak Site | Tor onion service (no auth) |
| Victims | BNI (Indonesia), Bank of Baroda (India) |
| Target Sector | Financial services (state-owned banks) |
| Geographic Focus | Asia-Pacific (Indonesia, India) |
| M.O. | Double extortion + public leak + full dump access |
| Date | Event |
|---|---|
| May 2026 | Triple X first observed / establishes leak infrastructure |
| May 11, 2026 | Claims breach of Bank Negara Indonesia (BNI) — ~2 TB data |
| June 2026 | Added to WatchGuard ransomware tracker as "data broker variant" |
| July 24, 2026 | Claims Bank of Baroda breach — ~1 TB, "weak password" attribution |
| July 25-26, 2026 | Full BoB dump publicly accessible on Tor — verified by CashlessConsumer |
Confidence: Low-to-Moderate. Triple X is very new with only 2 confirmed victims. No known ties to established ransomware families, state actors, or prior criminal groups.
Key unknowns: Is the "weak password" claim accurate? Does Triple X operate purely for profit or is there a geopolitical dimension? Are they a new independent group or a rebrand of an existing actor?
We cross-referenced the Tor dump directory listing against 9,992 BoB IFSC codes. Search your branch to see if customer data, KYC documents, or internal files from it were exposed.
🔍 Check Your Branch NowSearch by IFSC (e.g. BARB0VJABCD), branch name, or city
🔴 Phishing Scams
Expect fake calls, SMS, and emails pretending to be from BoB offering "protection" or asking you to "verify" your account. The leaked KYC data gives scammers everything they need to sound legitimate.
🔴 Loan Fraud
With KYC documents and loan records exposed, fraudsters may attempt to open loans in your name. Monitor CIBIL score regularly.
🟡 SIM Swap Attacks
Personal details in the dump enable SIM swap attacks. Contact your mobile provider to add extra verification.
🟡 Social Engineering
Scammers may reference specific transaction details from the dump. Never share OTPs or passwords.