The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.
No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.
Data breaches are the invisible catastrophes of the information age. Like radiation, breached data has no smell, no colour, no immediate sensation — but its effects compound over years: identity theft, financial fraud, social engineering, blackmail. The affected population numbers in the millions, yet official accounts are often sanitised, incomplete, or designed to minimise institutional liability rather than inform the public.
The historian Kate Brown, in Manual for Survival: A Chernobyl Guide to the Future, documents how the Soviet government suppressed the true scale of the Chernobyl disaster for decades. Official figures acknowledged 31 direct deaths from the explosion. Brown's decade-long archival investigation — cross-referencing hospital records, burial registries, and declassified KGB files — found evidence of hundreds of thousands of casualties from radiation exposure across Europe.[1]
The suppression was not accidental. It was structural: state institutions had incentives to minimise the disaster's scope. Independent researchers and journalists lacked access to affected zones. Official data was classified. The full truth emerged only through decades of citizen documentation — oral histories, independent health surveys, leaked government documents, and cross-border epidemiological studies.
Data breaches exhibit the same pattern.
Soviet authorities initially denied the Chernobyl explosion. When international radiation sensors detected the plume, they pivoted to damage control — blaming plant operators, downplaying radiation levels, and delaying evacuations. The official death toll (31) is still cited today, though independent researchers estimate the eventual death toll at 50,000 to 400,000 across Europe.[1]
Belarusian journalist Svetlana Alexievich spent years conducting over 500 interviews with Chernobyl survivors — firefighters, widows, scientists, evacuees, liquidators. Her book Voices from Chernobyl: The Oral History of a Nuclear Disaster (1997) was the first work to present the catastrophe through the lived experience of those it affected.[2]
Alexievich was awarded the 2015 Nobel Prize in Literature "for her polyphonic writings, a monument to suffering and courage in our time."[3] Her work is not a technical report. It is a documentary of human impact — the kind of record that government commissions and operator-authored post-mortems systematically exclude.
Historian Kate Brown's Manual for Survival (2019) revealed how the Soviet Union and later international agencies systematically suppressed evidence of Chernobyl's true health impact. Brown identified that United Nations agencies also downplayed findings about the epidemic that followed the disaster, partly because acknowledging widespread harm from Chernobyl risked exposing comparable damage from Western nuclear weapons testing.[1]
The lesson: official documentation of disasters is rarely complete, and never impartial. Every institution has incentive structures that shape what it reports.
When the Fukushima Daiichi nuclear plant melted down in March 2011, Japan's government and TEPCO (Tokyo Electric Power Company) had access to SPEEDI — a real-time radiation dispersal prediction system that could guide evacuations. They did not release the data. Investigative journalists later revealed that officials "played down the data, apparently fearful of having to significantly enlarge the evacuation zone — and acknowledge the accident's severity."[4]
Citizens in the affected zone were left to guess which areas were safe. Some, told the danger was minimal, evacuated straight into the path of radioactive fallout.
In response, Safecast was formed — a global, volunteer-driven citizen science project. Volunteers built and deployed hand-held Geiger counters, collected over 260 million environmental radiation measurements, and published them under an open CC0 license. Safecast data has since been validated against U.S. Department of Energy aerial surveys, showing high correlation.[5]
Today, Safecast operates over 5,000 devices across 102 countries, producing 66,000 daily measurements. Its data is used by researchers, municipalities, and international bodies. The project proved that citizens with sensors can generate data as reliable as state agencies — and make it public when authorities will not.[6]
This is citizen documentation of disaster in action. It is the same impulse that drives this site.
Days before the Bank of Baroda breach, Reuters reported that nearly 19,000 files totalling 14.3 GB relating to India's largest nuclear power plant — the Kudankulam Nuclear Power Plant (KKNP) in Tamil Nadu — had been exposed online. The data, breached from contractor Reliance Group, was publicly accessible on the dark web. Independent cybersecurity researcher Rakesh Krishnan, who first alerted Reuters, described the exposure as a serious national security risk.[7]
A senior director at the Nuclear Threat Initiative warned the leak could "show an adversary not just who has access to the project but which systems that access reaches." The breach underscored how cyber attacks have become routine in India, where many organisations remain ill-equipped to defend against or disclose them.[7]
The Kudankulam breach is a literal nuclear data incident. It demonstrates that in 2026, the boundary between "nuclear disaster" and "data breach" has collapsed — the latter is now a vector for the former.
On July 24, 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB of data from Bank of Baroda — India's second-largest public sector bank. The full dump, containing over 92,000 files across 9,783 directories, was published on a Tor leak site. The data includes customer KYC documents, audit reports, VAPT findings, loan records, and internal audits.[8]
The bank's response: a single press statement acknowledging a "cybersecurity incident" and assuring customers that their interests were "protected." No branch-level disclosure. No list of affected data types. No guidance on what customers should watch for. No individual notification. No public breach report.
This is the pattern across Indian data breaches. CERT-In receives notifications that never reach the public. Banks issue generic press releases. Affected consumers — the ultimate victims — are left to discover through news reports that their sensitive personal data may have been sold on the dark web.
India ranks third globally for data breaches, with 28.9 million accounts compromised in 2025 alone, behind only the United States and France.[9]
In every case, the affected population received minimal actionable information. Official accounts — when they exist — prioritise institutional reputation management over consumer protection.
History shows that when states and corporations are the sole arbiters of disaster documentation, the record is systematically incomplete. Institutions document what protects them. Citizens document what affects them.
Citizen documentation serves several essential functions:
The right to know what happened to one's own data is a consumer right and a civil right. In an era where personal data is the substrate of economic participation — banking, healthcare, identity verification — a data breach is not a technical incident. It is a mass harm event whose consequences compound over time, just like radiation exposure.
BoBBreach is a citizen documentation effort — an independent, consumer-focused investigation portal for the July 2026 Bank of Baroda data breach. It is built by CashlessConsumer, a fintech and digital public infrastructure research initiative.
What it is: A metadata-level analysis of the publicly available Tor dump directory structure. A search tool that lets affected consumers check if their branch IFSC appears in the breached dataset. An independent record that will persist regardless of institutional takedowns or changes to official accounts.
What it is not: It is not affiliated with Bank of Baroda, the Government of India, NPCI, CERT-In, or any law enforcement agency. It does not distribute PII from the dump. Its findings are indicative — based on file name patterns and directory structures, not content inspection. It makes no claim to completeness or infallibility. It is, in plain terms, best-effort disaster assistance built with AI and run by a consumer advocacy research project.
This site follows a tradition as old as Chernobyl survivors recording their testimonies and as new as Safecast volunteers mapping radiation that governments chose not to measure. When the institution that caused the harm is the only institution that speaks about it, the public cannot trust the account. Independent voices — even imperfect ones — are necessary.