🤖 LLM-Enabled Investigation

The research, data analysis, and narrative on this site were produced with the assistance of large language models (LLMs) as analytical tools. All metadata-driven findings (file names, directory structures, timestamps, document sizes) were extracted programmatically from the publicly available Tor dump and cross-referenced via automated scripts. Human researchers directed every query, verified every substantive claim, and maintained the editorial chain of custody.

No LLM has access to the actual contents of the dumped files — this is a metadata-level analysis of file names, paths, and document types visible in the leak directory structure. This is early, ongoing analysis and may contain errors. Independent verification is encouraged.

🔍 IFSC Branch Check

Was Your Branch Exposed?

Enter your Bank of Baroda IFSC code to check if your branch has confirmed data exposure in the Triple X dump. Branch data resolved by cross-referencing the dump's directory listing against the Razorpay IFSC database (9,992 BoB IFSC codes on record). Of these, 1,088+ branches matched files in the dump.

1,088+
Branches Impacted
248
Cities Affected
31
States & UTs
🗺️ Interactive map coming soon — click for details

A Leaflet.js map visualising all 1,088+ impacted branches across 248 cities in 31 states/UTs is in development. The map will show branch locations, cluster by region, and link directly to IFSC search results.
Priority: high · Blocked on geocoding pipeline for branch addresses.

Tip: All BoB IFSCs start with BARB0. You can also search by city, state, or branch name.

Enter a query above to search branches with confirmed data exposure.

🔬 Methodology & How This Was Built

This branch checker matches file paths observed in the publicly available Triple X Tor dump directory listing against the Razorpay IFSC database.

Step 1 — Dump crawl
We crawled the directory structure visible on the Triple X Tor leak server. File names, paths, and metadata were recorded. No actual file contents were downloaded or accessed.

Step 2 — IFSC extraction
File paths in the dump frequently contain IFSC codes, branch codes, city names, or region abbreviations embedded in folder and document names. These were extracted programmatically.

Step 3 — Cross-reference
Extracted branch identifiers were matched against the Razorpay IFSC database, which lists ~9,992 active BoB IFSC codes. This maps exposed files to specific branches, cities, and states.

Step 4 — Validation
Matches were manually reviewed against directory naming patterns. Some branches may have data in the dump without a resolvable IFSC pattern in file paths — this dataset undercounts rather than overcounts.

⚠️ Important caveats:
  • Metadata only — counts reflect file paths in the directory listing, not file content
  • Indicative numbers — branch counts are from initial ongoing analysis and may change as we refine mapping
  • File server ≠ core banking — this maps what was on the compromised SharePoint, not the Finacle database. Customers of branches not in this dataset may still be affected via other systems

Understanding Results

⚠️ EXPOSED
Your branch had files in the dump. Risk varies by data type found — from KYC/PII (critical) to operational documents (medium).

❓ NOT FOUND
No files from this branch were found. May still be affected — the dump covers the file server, not the core banking system.

Recommended Actions

  • Monitor all BoB account transactions
  • Change net banking password & enable 2FA
  • Freeze credit report (CIBIL, Experian, Equifax)
  • Be alert for phishing targeting leaked data
  • Full consumer guide →

Browse by State

Filter impacted branches by state to see the geographic scope of exposure.