Bank of Baroda Data Breach: 700 GB to 1 TB of Alleged Banking Data Leaked

Bank of Baroda data breach has placed India’s banking sector under the cybersecurity spotlight after researchers discovered a massive archive of allegedly stolen banking data on a dark web forum. The incident came to light after cybersecurity researchers discovered a large archive of allegedly stolen bank data being advertised on a dark web forum. Initial reports suggest the exposed dataset could range from 700 GB to 1 TB, making it one of the largest publicly reported banking data leaks in the country.

The leaked files allegedly contain a wide range of sensitive information, including customer details, Aadhaar information, account records, loan documents, internal audit files, and corporate banking data. While the authenticity and completeness of every leaked file are still being verified, the scale of the incident has raised significant concerns among customers, regulators, and cybersecurity professionals alike.

The breach serves as a reminder that even highly regulated financial institutions remain attractive targets for cybercriminals due to the volume and sensitivity of the information they manage.

How Did the Bank of Baroda Data Breach Happen?

The exact attack chain is still under investigation. Still, Bank of Baroda has stated that the incident originated from the compromise of an employee’s email account rather than its core banking infrastructure. According to The Hindu, there is currently no evidence suggesting that its core banking systems were directly breached.

Despite this statement, cybersecurity researchers have questioned whether the compromise of a single email account alone could explain the reported volume of leaked data. It is possible that attackers leveraged the compromised account to gain broader access to internal repositories, shared drives, or confidential documents before exfiltrating the information. Until forensic investigations are complete, the full extent of the attack remains unclear.

The stolen data was reportedly advertised and shared through dark web marketplaces and cybercriminal forums, where threat actors commonly sell or distribute stolen information. These underground platforms allow cybercriminals to monetise compromised data by selling it to other malicious actors, who may use it for financial fraud, identity theft, phishing campaigns, or further attacks against organisations.

Even when financial systems themselves remain uncompromised, the exposure of customer and internal business data can have serious

long-term consequences, particularly when the information is circulated across multiple threat actor communities.

also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

Bank of Baroda Responds to the Alleged Data Breach

Bank of Baroda responded by acknowledging that a cybersecurity incident had occurred while assuring customers that its core banking infrastructure had not been compromised. The bank stated that the breach was limited to

an employee’s email account and emphasised that customer deposits, banking operations, and payment services remained unaffected.

The organisation has initiated a forensic investigation to determine the full scope of the incident and is working alongside cybersecurity experts and relevant authorities. As part of its response, the bank has also implemented additional monitoring measures and is assessing the impact on affected individuals.

For customers, the bank has advised them to remain vigilant against phishing attempts and fraudulent communications that may exploit the leaked information. Security experts similarly recommend changing online banking passwords, enabling multi-factor authentication wherever possible, and monitoring accounts for any unusual activity.

Although investigations are ongoing, the incident demonstrates how quickly an initial compromise can escalate into a large-scale data exposure if privileged accounts or sensitive repositories become accessible.

also read: What the CDSL Malware Attack Teaches Organizations About VAPT?

What Businesses Can Learn from the Bank of Baroda Data Breach

Financial institutions are not the only organisations at risk. Every business that stores customer records, payment information, employee data, or financial documents has become a valuable target for cybercriminals.

Protecting financial data requires far more than perimeter security. Businesses should adopt a layered security strategy that includes strong identity and access management, multi-factor authentication, email security, continuous vulnerability management, regular security awareness training, data encryption, and continuous monitoring for suspicious activity. Limiting user privileges and implementing zero trust principles can also significantly reduce the impact of compromised accounts.

What the CDSL Malware Attack Teaches Organizations About VAPT?

Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing (VAPT) exercise is enough to satisfy cybersecurity requirements. The 2022 malware attack on Central Depository Services Limited (CDSL) tells a very different story. Despite undergoing a VAPT assessment only months before the incident, CDSL experienced a malware attack that disrupted settlement operations across India’s securities market.

Following an extensive forensic investigation, the Securities and Exchange Board of India (SEBI) identified multiple security control failures that enabled attackers to compromise the environment and remain undetected. The investigation revealed a recurring theme. The issue was not the absence of cybersecurity investments. The organization had security tools, endpoint protection, and periodic VAPT assessments. The problem was that one system was excluded from critical security controls.

That overlooked system became the attacker’s entry point. For organizations planning Vulnerability Assessment and Penetration Testing, the CDSL incident demonstrates an important reality.

 “ A VAPT assessment will only be effective when all the critical and non critical systems are included within its scope

When One Server Becomes the Weakest Link

Every major cyber incident has a beginning. In the CDSL attack, investigators traced the compromise back to an Azure-hosted Active Directory Federation Services (ADFS) server that had been deployed during the COVID 19 remote working period.

Originally introduced to enable secure remote authentication and single sign-on capabilities, the server gradually became part of the production environment.

Unfortunately, it never became part of the organization’s security perimeter.

According to the SEBI investigation, the ADFS server:

  • Was internet-facing.
  • Was not classified as a critical asset.
  • Was excluded from Vulnerability Assessment and Penetration Testing.
  • Was not integrated into the Security Information and Event Management (SIEM) platform.
  • Was not protected through Privileged Identity Management (PIM).
  • It had weak, non-expiring admin credentials. A domain-admin account had an easily guessable password set to “never expire.” 
  • The RDP port was left open to the internet.

Attackers exploited this single gap to gain access without triggering any meaningful security alerts.

This incident demonstrates why effective Vulnerability Assessment and Penetration Testing (VAPT) should start with comprehensive asset discovery. Security assessments limited to known production systems can overlook unmanaged or forgotten assets that significantly increase an organization’s attack surface.

also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

What Happened During the November 2022 CDSL Malware Attack?

On 18 November 2022, shortly after end-of-day processing completed, CDSL detected that several servers and employee workstations had become inaccessible due to a malware attack.

As part of its incident response, the organization isolated compromised systems, segmented affected network areas, and restored critical infrastructure within a newly deployed, clean virtual LAN (VLAN) environment to prevent further spread and support secure recovery.

Although containment prevented wider propagation across market participants, several critical depository services experienced significant disruption. Because of the disruption, settlement transactions originally planned for 18 November were postponed until 20 November. The delay affected normal settlement operations and temporarily disrupted activities across India’s securities ecosystem.

The incident demonstrated how a cybersecurity event affecting a single organization can rapidly impact an entire financial market.

How One Overlooked Internet-Facing Server Became the Initial Attack Vector

The SEBI forensic investigation identified asset visibility as one of the primary factors behind the CDSL malware attack. An internet-facing Active Directory Federation Services (ADFS) server was not classified as a critical asset, despite being externally accessible. This single oversight created multiple security gaps that attackers exploited.

Because the server was excluded from the organization’s critical asset inventory, it was also left out of the Vulnerability Assessment and Penetration Testing (VAPT) scope. In addition, its logs were not integrated with the SIEM platform, Privileged Identity Management (PIM) controls were not implemented, and security monitoring did not adequately cover the system. As a result, the attackers gained access and operated with minimal visibility before the incident was detected.

This incident demonstrates an important cybersecurity lesson: an organization’s attack surface extends to every internet-facing asset. If even one externally accessible system is overlooked during asset discovery or excluded from VAPT, it can become the initial attack vector that puts the entire environment at risk.

Also read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

Five Critical Security Gaps Identified by the SEBI Investigation

1. Internet-Facing Infrastructure Outside the VAPT Scope

SEBI’s investigation concluded that the ADFS server should have been classified as a critical internet-facing system under updated regulatory guidance.

Because it was excluded, the organization’s security assessment never evaluated its attack surface.

External Penetration Testing should always include:

  • Internet-facing authentication servers
  • VPN gateways
  • Remote access infrastructure
  • Cloud-hosted virtual machines
  • Identity services

One missing asset can invalidate an otherwise successful security assessment.

2. Exposed Remote Desktop Protocol (RDP)

Investigators also found that network vulnerability assessment scanning had not been performed against the affected infrastructure. As a result, an internet accessible Remote Desktop Protocol (RDP) service remained exposed.

The exposed RDP service provided attackers with a pathway into the environment that should have been identified during External Infrastructure VAPT.

3. Weak Privileged Credentials

The forensic investigation identified multiple privileged access weaknesses, including:

  • Weak administrative password
  • Password configured to never expire
  • Long-term privileged access
  • Excessive administrative permissions

These weaknesses enabled attackers to maintain persistence after the initial compromise. Modern Penetration Testing should never focus solely on software vulnerabilities. Privilege escalation testing and identity security reviews are equally important.

4. Missing Multi-Factor Authentication

The compromised system lacked two-factor authentication for remote administrative access. Even when attackers obtain credentials, MFA significantly increases the difficulty of successful compromise. Identity protection should always complement Vulnerability Assessment.

5. SIEM Visibility Gaps

One of the most significant findings of the SEBI investigation was that the compromised server was not integrated with the organization’s Security Information and Event Management (SIEM) platform. As a result, security logs from the server were not collected or correlated, allowing malicious activity to continue without effective detection. The investigation also noted that alerts generated by existing security tools were not properly acknowledged or investigated, delaying the organization’s response to the attack.

This incident highlights the complementary roles of Vulnerability Assessment and Penetration Testing (VAPT) and a Security Operations Center (SOC). While VAPT helps identify and remediate security weaknesses before attackers can exploit them, a SOC continuously monitors systems to detect and respond to active threats. Organizations need both proactive security testing and continuous monitoring to build a resilient cybersecurity posture.

Why the Existing VAPT Failed to Prevent the Attack

One of the most important lessons from the CDSL incident is that the organization had already completed a Vulnerability Assessment and Penetration Testing (VAPT) exercise several months before the malware attack. However, the investigation found that the issue was not how often VAPT was conducted, but what it covered. The internet-facing ADFS server, the attackers’ entry point, was excluded from the assessment scope, leaving a critical gap in the organization’s security posture.

This highlights an important reality for security leaders: a clean VAPT report does not automatically mean an organization is secure. It only reflects the systems, applications, and infrastructure that were actually tested. If critical internet-facing assets are omitted, significant vulnerabilities can remain undiscovered until attackers exploit them.

The Business Impact: How the CDSL Cyberattack Disrupted Market Operations

The technical compromise quickly evolved into an operational crisis.

According to the SEBI order:

  • Settlement processes were disrupted for approximately 46 hours.
  • Inter-depository transfers remained unavailable for more than 54 hours.
  • Corporate actions, pledge processing, and off-market transfers were delayed.
  • Critical market settlement activities scheduled for 18 November were completed only on 20 November through coordinated recovery efforts.

The incident illustrates how cybersecurity failures can extend far beyond IT systems and directly affect business continuity, regulatory compliance, and customer confidence.

Five Cybersecurity Lessons Every Organization Should Learn from the CDSL Attack

NoCybersecurity LessonKey Takeaway
1Maintain a Complete Inventory of Internet-Facing AssetsIdentify, classify, and continuously monitor every internet-facing server, application, and service to eliminate blind spots.
2Include Every Critical System Within the VAPT ScopeEnsure all critical infrastructure, identity services, and externally accessible assets are included in every VAPT assessment.
3Perform Both External and Internal Penetration TestingCombine External Penetration Testing to identify attack vectors with Internal Penetration Testing to uncover privilege escalation and lateral movement risks.
4Validate Remediation After Every AssessmentConfirm that identified vulnerabilities have been successfully remediated and can no longer be exploited.
5Combine VAPT with Continuous Security MonitoringPair Vulnerability Assessment and Penetration Testing (VAPT) with continuous Security Operations Center (SOC) monitoring to detect and respond to threats in real time.

How SecuCenter Helps Organizations Strengthen Their Security Posture

At SecuCenter, we approach Vulnerability Assessment and Penetration Testing as a continuous risk reduction program rather than a compliance exercise.

Our VAPT services include:

  • Vulnerability Assessment
  • External Penetration Testing
  • Internal Penetration Testing
  • Network VAPT
  • Web Application Penetration Testing
  • API Security Testing
  • Cloud Security Assessment
  • Active Directory Security Assessment
  • Infrastructure Security Assessment
  • Wireless Security Testing
  • Configuration Review
  • Remediation Validation
  • Executive Reporting
  • Compliance Ready Reporting
  • Managed VAPT Services

Our assessments are designed to identify overlooked assets, validate real-world attack paths, and provide actionable remediation guidance before threat actors discover the same weaknesses.

Also read: A Critical Vulnerability Rating of 10/10 Has Been Confirmed By Microsoft

The Biggest Cybersecurity Risk Is Often the System You Forgot to Test

The CDSL malware attack is more than a story about malware. It is a reminder that cybersecurity failures often begin with overlooked assets, incomplete visibility, and assumptions about what is or is not critical. One internet-facing authentication server, excluded from Vulnerability Assessment and Penetration Testing, became the initial foothold that enabled attackers to disrupt one of India’s most critical financial infrastructures.

Organizations should not treat VAPT as a once-a-year compliance requirement. Effective security requires continuous asset discovery, comprehensive testing of external and internal attack surfaces, timely remediation, and ongoing monitoring.

The most valuable lesson from the CDSL incident is simple:

Attackers only need one system that defenders forgot to test.

The Human Firewall: What Kevin Mitnick Can Teach Us About Financial Fraud Today

The world’s most famous hacker never needed to “hack” much

Kevin Mitnick spent years as the FBI’s most-wanted computer criminal, breaking into networks at Nokia, Motorola, Sun Microsystems, and Pacific Bell. But the uncomfortable truth in his own account of that era is this: most of his access didn’t come from exploiting code. It came from exploiting people.

He’d call an employee, sound confident, use the right internal jargon, claim to be from IT or a manager under pressure, and ask for what he needed. A password. A callback number. A “quick favor.” He called this social engineering, and he was so effective at it that prosecutors reportedly told a judge he could start a nuclear war by whistling into a payphone. That claim was absurd. But the underlying fear it revealed wasn’t: that a sufficiently convincing human voice can bypass almost any technical safeguard.

Mitnick spent the years after prison until he died in 2023 teaching companies exactly this lesson through his books and security consulting work: the strongest firewall in the world means nothing if someone can be talked past it.

Nowhere is that more true today than in financial fraud.

How Social Engineering Evolved into Modern Financial Fraud

The techniques Mitnick pioneered on landlines in the 1990s haven’t gone away. They’ve been repackaged for online banking, mobile payments, and messaging apps. The core move is unchanged: create urgency and get the target to act before they think.

A few patterns are dominating financial fraud across the US, UK, and Australia right now:

  • Bank impersonation scams -A call, text, or email claims to be from your bank’s fraud department, warning of “suspicious activity” and asking you to “verify” your account, move money to a “safe account,” or read out a one-time passcode. In the UK, this is often called authorised push payment (APP) fraud; you’re persuaded to send the money yourself, so it doesn’t look like a traditional hack.
  • Government and tax authority impersonation -Callers or emails pose as the IRS (US), HMRC (UK), or the ATO (Australia), claiming unpaid tax, a legal case, or a refund that requires “verification” of your bank details or an urgent payment via gift cards or crypto.
  • Tech support scams -A pop-up or cold call claims your computer is infected and remote access is needed to “fix” it; the access is then used to move money out of your accounts while you watch.
  • Romance and investment scams -Relationships built over weeks or months on dating apps or social media, eventually pivoting to requests for money, or introducing a “guaranteed” cryptocurrency or trading opportunity (sometimes called pig butchering scams).
  • Business Email Compromise (BEC) -Fraudsters impersonate a company executive, supplier, or solicitor/lawyer by email, asking finance staff to urgently change bank details on an invoice or wire funds for a “confidential deal.”

Every one of these succeeds the same way Mitnick’s calls did decades ago, not by breaking encryption, but by breaking judgment under manufactured pressure.

Why Social Engineering Works on Smart People

One of Mitnick’s most repeated points, later echoed across the security industry, is that social engineering isn’t about tricking gullible people; it’s about exploiting normal, healthy human instincts:

  • Trust in authority: we’re conditioned to comply when someone claims to be a bank, the police, or a government agency.
  • Fear and urgency: panic shuts down the part of the brain that would otherwise pause and verify.
  • Reciprocity and rapport: a friendly, patient scammer who “helps” you first earns the trust needed to ask for more later.
  • Technical intimidation: most people won’t challenge someone who sounds like they understand banking or IT systems better than they do.

None of this requires a single line of malicious code. It requires a script, a phone, and a target who hasn’t been trained to pause.

How to Build a Human Firewall Against Social Engineering Attacks

Mitnick’s later career was built on a simple premise: organizations spend heavily on technical controls and comparatively little on preparing people to recognize manipulation. The same gap shows up individually with financial fraud. A few habits close most of it:

a) Verify Independently, Never Through the Channel That Contacted You

If a call, text, or email claims to be your bank or a government agency, hang up and call the organization back using the number on the back of your card, or the official number from their website — never one given to you during the contact.

b)Authority Claimed Over the Phone, or Email Means Nothing on Its Own

Legitimate banks and tax authorities do not ask you to move money to a “safe account,” do not request one-time passcodes, and do not demand payment via gift cards, wire transfer, or cryptocurrency.

c) Urgency Is the Tell, Not the Threat

Legitimate institutions rarely require you to act within minutes. Pressure to skip verification is itself the strongest signal something is wrong.

d) No Legitimate Needs Your One-Time Passcode, PIN, or Full Card Details Ever

Not your bank, not “IT support,” not a “financial advisor” you’ve never met in person.

e) Treat Unsolicited Financial Opportunities with the Same Suspicion as Unsolicited Threats

Guaranteed investment returns, unexpected romantic interest that turns into financial requests, “insider” trading tips these use the same rapport-building playbook as impersonation scams, just with a friendlier tone.

What to Do If You’ve Been Targeted by a Social Engineering Scam

In all three countries, speed matters; funds can sometimes still be frozen or recalled if reported within the first hours after a transfer.

Kevin Mitnick’s Lasting Lesson for Cybersecurity and Financial Fraud Prevention

Mitnick’s own transformation from the person exploiting trust to the person teaching organizations how to defend against it carried one consistent message: technology can be patched, but human trust has to be trained. Banks harden their systems every year. Fraudsters don’t bother trying to break them. They call the person holding the account instead, because it’s still the easiest way in.

The best defense against social engineering isn’t smarter technology. It’s a habit of pausing, verifying independently, and refusing to let urgency decide for you.

Protect Your Business Today To Scale Tomorrow

Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.

Phone

+1 607 360 5504

Sales Office - United States

651, N Broad St, Middletown
Delaware-19709

Operations Center- India

Level 17, TransAsia Cyber Park
Kochi, Kerala-682030

Data privacy notice. All submissions are protected via TLS 1.3 encryption in transit and processed within our secure, air-gapped data environment. We never resell your data.