Customer data from India’s Bank of Baroda leaked online, source and researcher say


By Gopika Gopakumar and Ashwin Manikandan

MUMBAI, July 27 (Reuters) – Customer data from India’s state-run Bank of Baroda, along ‌with internal documents, has been leaked on the dark ‌web, according to a source familiar with the matter and a cybersecurity ​researcher.

The leaked data includes customer details, identification documents, loan papers and internal audit records, said cybersecurity researcher Srikanth L, founder of Cashless Consumer.

A source familiar with the matter confirmed the leak and ‌said the bank ⁠was conducting a forensic audit.

It was not immediately clear how many customers were affected. Bank of ⁠Baroda has not notified stock exchanges of any breach.

Bank of Baroda, the Reserve Bank of India and India’s cybersecurity regulator CERT-In ​did not ​immediately respond to requests for ​comment.

The leak comes amid growing ‌concerns over cybersecurity risks facing large companies and financial institutions that store vast amounts of customer and business data.

Preliminary indications suggest the incident stemmed from a compromised email system, the source said.

The data appeared on a dark web site on ‌Saturday night and was advertised as ​a cache containing more than 700 ​gigabytes of information, based ​on metadata analysis of the site, Srikanth said.

In ‌June, a cyberattack on Apple supplier ​Tata Electronics led ​to component design and specification documents linked to Apple and Tesla being leaked on the dark web.

Earlier this month, ​ransomware group World ‌Leaks posted files on the dark web related to ​India’s largest nuclear plant.

(Reporting by Gopika Gopakumar and Ashwin ​Manikandan. Editing by Mark Potter)



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *