New Delhi, July 28 -- Public sector lender Bank of Baroda (BoB) has launched a forensic investigation after confirming that a compromised employee email account led to unauthorised access to "certain data", even as reports claimed that more than 700 GB-and possibly close to 1 TB-of information had surfaced on the dark web. The bank has maintained that its core banking systems remain unaffected and is assessing the extent of the incident through a forensic probe.

The alleged leak has drawn attention because reports suggest the exposed dataset could include customer names, Aadhaar numbers, PAN details, account records, loan information, net banking data, NRI and corporate banking records, as well as internal audit documents. The bank, however, has not independently verified the authenticity or contents of the leaked files. Here's what enterprise leaders need to know about the incident, the cybercrime ecosystem behind data breaches, and the lessons for prevention and resilience.

What does a forensic investigation seek to establish?

A forensic investigation reconstructs the cyberattack to determine how attackers gained access, how long they remained inside the network, what systems they reached and whether any information was copied or exfiltrated. Investigators analyse system logs, email records, authentication trails and network activity to establish whether the breach was confined to a compromised email account or extended deeper into the organisation, and whether any attacker still retains access.

Why would Aadhaar or KYC data be a prized target?

If identity documents such as Aadhaar, PAN, passport details, KYC records, addresses, phone numbers or account information are indeed compromised-as alleged in reports but not officially confirmed-they become significantly more valuable than passwords alone.

Cybercriminals often combine such information with data from previous breaches to build complete digital identities that can be used for identity theft, financial fraud, fraudulent loan applications, SIM-swap attacks and highly targeted phishing campaigns. Unlike payment card details, which can be quickly blocked, identity information can retain value for years because it can be reused or resold multiple times.

What happens after data is stolen?

Modern cyberattacks are increasingly focused on data theft rather than simply encrypting systems. Attackers typically spend days or weeks moving through a victim's network, identifying valuable databases before quietly transferring information outside the organisation. Only then do they demand ransom or threaten to leak the data publicly.

Even organisations that successfully recover their systems from backups may still face extortion because criminals can monetise stolen information by publishing or selling it.

What exactly is the dark web?

The dark web is a hidden part of the internet that requires specialised software, such as Tor, to access. While it has legitimate privacy uses, it has also become a marketplace for stolen databases, compromised credentials and ransomware operations. Attackers frequently publish samples of stolen information to prove authenticity before offering complete datasets for sale or auction. A similar pattern emerged recently when reports claimed alleged DRDO and military data had been offered on the dark web for $8,000, prompting authorities to first verify the authenticity of the claims before commenting on the reported breach.

Is India seeing more such incidents?

The Bank of Baroda case adds to a growing list of cyber incidents involving Indian organisations. The ransomware attack on AIIMS Delhi in 2022 disrupted healthcare services for weeks, while the alleged exposure of ICMR data in 2023 highlighted the risks associated with large public databases. In the private sector, consumer electronics brand boAt also reportedly saw customer information-including names, addresses, email IDs and phone numbers-appear on the dark web in 2024.These incidents reflect a broader shift in cybercrime-from disrupting systems to monetising sensitive information.

What are the key takeaways for the C-suite from the Bank of Baroda incident?

The reported breach reinforces why cybersecurity is increasingly becoming a business resilience issue rather than solely an IT challenge. Rajesh Chhabra, General Manager, APAC, Large Markets at Acronis, says banks should assume sophisticated attacks are a matter of when, not if. As financial institutions accelerate digital transformation and expand interconnected ecosystems, protecting customer data, critical systems and third-party relationships becomes increasingly complex.

According to Chhabra, the differentiator is no longer preventing every attack but how quickly organisations detect suspicious activity, contain its impact, recover operations and maintain customer trust. That requires continuous security monitoring, strong identity and access controls, rigorous third-party risk management, immutable and regularly tested backups, and incident response plans that are regularly exercised rather than merely documented.

The forensic investigation will determine the true scale of the Bank of Baroda incident. But irrespective of its findings, the episode underscores a larger reality. In today's cybercrime economy, data has become as valuable as money itself, making cyber resilience a boardroom priority rather than just an IT function.

Published by HT Digital Content Services with permission from TechCircle.