Bank of Baroda Confirms Incident After Threat Actor Claims Data Theft
One of India's largest state-owned financial institutions, **Bank of Baroda**, has disclosed a cybersecurity incident following claims by a threat actor of having exfiltrated and published sensitive banking data. The bank states an employee's email was compromised, but core banking systems remain secure. This incident highlights a growing trend of cyberattacks targeting major financial entities and critical infrastructure across Asia.
# Bank of Baroda Confirms Incident After Threat Actor Claims Data Theft
**Bank of Baroda** has confirmed a cybersecurity incident after a threat actor, operating under the moniker "leak-king-F," claimed to have stolen and published sensitive banking data. The bank stated that an employee's email account was compromised, leading to unauthorized access to "certain data."
## Incident Detected and Contained
The bank emphasized that the incident was detected and contained immediately, and its core banking systems were not accessed or affected. An ongoing investigation aims to fully understand the scope and impact of the breach.
## Dark Web Claims and Data Authenticity
Last week, cybersecurity researchers tracking dark web activity reported that an unidentified hacker had purportedly breached the bank. The threat actor subsequently leaked what they described as customer information, corporate banking records, internal emails, loan documents, and audit files on a darknet forum. The authenticity of this purportedly leaked data has not been independently verified, and **Bank of Baroda** has not commented on the hacker's specific claims or confirmed any customer data exfiltration.
"Leak-king-F" reportedly offered the data for sale on a popular darknet marketplace, directing prospective buyers to a Telegram channel.
## Broader Regional Cyber Threats
This incident at **Bank of Baroda** is the latest in a series of cyberattacks impacting major financial institutions and companies across Asia.
Last week, Thailand's Securities and Exchange Commission launched an investigation into a data breach at the **Thailand Securities Depository (TSD)**. Hackers claimed to have stolen investor information after compromising an investor portal. **TSD** confirmed unauthorized access to customer data but stated that its trading, settlement, and depository systems were unaffected.
Earlier this month, the ransomware and extortion group **World Leaks** published thousands of files allegedly stolen from contractors working on India's largest nuclear power project. India's state-owned nuclear operator confirmed the documents did not affect plant safety or security, appearing to originate from a third-party company building conventional infrastructure.
Separately, **World Leaks** also claimed responsibility for an attack on **Tata Electronics**, a key supplier to **Apple**, **Tesla**, and **Qualcomm**. The group demanded a $1.5 million ransom and subsequently published what it claimed were confidential engineering documents after alleging that the company refused to negotiate.