Bank of Baroda Data Breach: 700 GB to 1 TB of Alleged Banking Data Leaked

Bank of Baroda data breach has placed India’s banking sector under the cybersecurity spotlight after researchers discovered a massive archive of allegedly stolen banking data on a dark web forum. The incident came to light after cybersecurity researchers discovered a large archive of allegedly stolen bank data being advertised on a dark web forum. Initial reports suggest the exposed dataset could range from 700 GB to 1 TB, making it one of the largest publicly reported banking data leaks in the country.

The leaked files allegedly contain a wide range of sensitive information, including customer details, Aadhaar information, account records, loan documents, internal audit files, and corporate banking data. While the authenticity and completeness of every leaked file are still being verified, the scale of the incident has raised significant concerns among customers, regulators, and cybersecurity professionals alike.

The breach serves as a reminder that even highly regulated financial institutions remain attractive targets for cybercriminals due to the volume and sensitivity of the information they manage.

How Did the Bank of Baroda Data Breach Happen?

The exact attack chain is still under investigation. Still, Bank of Baroda has stated that the incident originated from the compromise of an employee’s email account rather than its core banking infrastructure. According to The Hindu, there is currently no evidence suggesting that its core banking systems were directly breached.

Despite this statement, cybersecurity researchers have questioned whether the compromise of a single email account alone could explain the reported volume of leaked data. It is possible that attackers leveraged the compromised account to gain broader access to internal repositories, shared drives, or confidential documents before exfiltrating the information. Until forensic investigations are complete, the full extent of the attack remains unclear.

The stolen data was reportedly advertised and shared through dark web marketplaces and cybercriminal forums, where threat actors commonly sell or distribute stolen information. These underground platforms allow cybercriminals to monetise compromised data by selling it to other malicious actors, who may use it for financial fraud, identity theft, phishing campaigns, or further attacks against organisations.

Even when financial systems themselves remain uncompromised, the exposure of customer and internal business data can have serious

long-term consequences, particularly when the information is circulated across multiple threat actor communities.

also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

Bank of Baroda Responds to the Alleged Data Breach

Bank of Baroda responded by acknowledging that a cybersecurity incident had occurred while assuring customers that its core banking infrastructure had not been compromised. The bank stated that the breach was limited to

an employee’s email account and emphasised that customer deposits, banking operations, and payment services remained unaffected.

The organisation has initiated a forensic investigation to determine the full scope of the incident and is working alongside cybersecurity experts and relevant authorities. As part of its response, the bank has also implemented additional monitoring measures and is assessing the impact on affected individuals.

For customers, the bank has advised them to remain vigilant against phishing attempts and fraudulent communications that may exploit the leaked information. Security experts similarly recommend changing online banking passwords, enabling multi-factor authentication wherever possible, and monitoring accounts for any unusual activity.

Although investigations are ongoing, the incident demonstrates how quickly an initial compromise can escalate into a large-scale data exposure if privileged accounts or sensitive repositories become accessible.

also read: What the CDSL Malware Attack Teaches Organizations About VAPT?

What Businesses Can Learn from the Bank of Baroda Data Breach

Financial institutions are not the only organisations at risk. Every business that stores customer records, payment information, employee data, or financial documents has become a valuable target for cybercriminals.

Protecting financial data requires far more than perimeter security. Businesses should adopt a layered security strategy that includes strong identity and access management, multi-factor authentication, email security, continuous vulnerability management, regular security awareness training, data encryption, and continuous monitoring for suspicious activity. Limiting user privileges and implementing zero trust principles can also significantly reduce the impact of compromised accounts.

Bitdefender Acquires Mesh Security to Enhance MDR and Email Threat Protection for MSPs

June 19, 2025: In a massive twist of events, Bitdefender has announced their acquisition of Mesh Security Limited, a known email security startup headquartered in Ireland, to be soon merged with its GravityZone XDR. This acquisition strengthens Bitdefender’s position in protecting one of the most frequently exploited attack surfaces, email while reinforcing its focus on the managed services market.

Why Email Security Is a Critical Layer

Email continues to be a primary entry point for ransomware, phishing, business email compromise, and credential theft. Attackers have evolved their techniques, rendering traditional perimeter-based defenses less effective. Through this acquisition, Bitdefender will enhance its GravityZone XDR and MDR platforms by incorporating Mesh’s layered email protection and telemetry.

What Sets Mesh Security Apart

Founded in 2020, Mesh Security was purpose-built to tackle modern email threats in cloud environments, with a strong focus on serving MSPs.

The platform offers a dual-layered protection model. The secure email gateway at the perimeter effectively filters out known threats, enhancing our overall security posture.  At the mailbox level, Mesh connects via API to continuously scan and act on suspicious messages that make it past initial filters. This enables real-time visibility and remediation inside tools like Microsoft 365 and Google Workspace.

Mesh is also known for its clean design, automation features, and MSP-native functionality. Multi-tenant support, policy templates, and integrations with popular PSA and RMM platforms like ConnectWise and Kaseya help MSPs deploy and manage the service with ease and efficiency.

What Bitdefender Gains from the Acquisition

Bitdefender intends to integrate Mesh directly into the GravityZone platform. The goal is to extend its XDR and MDR services to include email telemetry, which provides better threat correlation across endpoints, cloud, and inboxes.

This addition closes a major gap in Bitdefender’s threat coverage and transforms GravityZone into a more complete and connected defense system. It improves threat visibility, accelerates investigation processes, and enhances the efficiency of automated responses.

Also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

Commitment to Existing Mesh Partners

Amid the integration, Bitdefender has confirmed that Mesh leadership and core team will be the same as they continue to grow the platform. For MSPs currently using Mesh, there will be no pricing changes for the next 24 months. The roadmap will continue with added investment in support, engineering, and feature development.

This continuity has been well-received by MSP partners who value consistency and clarity in vendor relationships.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

Part of a Larger Growth Strategy

Bitdefender has been expanding rapidly over the past two years. It acquired Singapore-based Horangi Cyber Security in 2023 and made further inroads into Asia through its 2025 deal with BitShield.

The acquisition of Mesh Security represents a significant opportunity to enhance our product offerings and address an important gap in our portfolio. With email defense now in place, Bitdefender has become a more comprehensive vendor for organizations and MSPs seeking a single-source solution for security.

Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft

Market Reaction and Future Outlook

MSPs that rely on Mesh have praised its ease of use, reliability, and alignment with partner needs. The challenge now is to maintain that agility and MSP-first approach as the platform scales under Bitdefender’s brand.

Bitdefender’s move reflects a shift toward fully integrated cybersecurity stacks that are easier to manage and harder for attackers to evade. Email security is no longer optional. With Mesh, Bitdefender is delivering what the market demands: complete protection that connects every part of the security journey.

SecuCenter’s Take

At SecuCenter, we view this acquisition as a timely and strategic enhancement to Bitdefender’s XDR capabilities. Mesh Security’s layered defense model fills a long-standing visibility gap between endpoint and cloud, especially within email communications.

This acquisition will convert the inbox from a weak link into a key source of threat intelligence. As a provider of white-label SOC monitoring and SOC staffing, we see clear synergy, i.e., our analysts can leverage this added telemetry to deliver more precise alerts, faster correlation, and stronger remediation guidance for MSPs and their clients.

Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

On May 15, 2025, Coinbase acknowledged its most serious security lapse to date, a breach that could ultimately cost the exchange as much as $400 million and has compromised records for more than 69,000 customers. Investigators traced the incident to an overseas contact center operation: hackers bribed a handful of support agents in Indore, India, to capture screenshots and copies of customer data stored in internal systems.

Those agents worked for TaskUs, a U.S.–headquartered BPO firm that has handled Coinbase support queues since 2017. According to multiple reports, the attackers, described as a loose network of young, English-speaking cybercriminals, offered cash incentives to TaskUs employees willing to leak sensitive information, including names, email addresses, and partial account details.

A Breach Months in the Making

Internal logs show Coinbase first spotted suspicious activity months before the disclosure. By January 2025, the exchange had quietly asked TaskUs to dismiss 226 agents from its Indore office, many of whom were later linked to the leak. When criminals attempted to extort Coinbase on May 11, the company cut the remaining ties, tightened access controls, and publicly confirmed the breach four days later.

Although no passwords, private keys, or crypto balances were exposed, the stolen data is still valuable for targeted phishing and social engineering schemes. In response, Coinbase posted a $20 million reward for information leading to the perpetrators and pledged to reimburse any customers tricked into sending funds to attackers.

The Weak-Link Problem in Outsourced Support

This event underscores how quickly a single compromised vendor can undermine even a well-resourced security program. With call center staff often granted broad view access to resolve user tickets, bribery, extortion, or simple negligence can open the door to large-scale data theft.

How MSPs and MSSPs Can Help Businesses Respond and Prepare

Vendor-Access Hardening

Perform stringent due diligence reviews of every third-party help desk or BPO partner. Enforce least-privilege access, screen for insider-threat indicators, and require periodic audits that map who can see customer data and why.

Zero-Trust Architecture

Implement identity-centric controls so support personnel must re-authenticate for sensitive actions, and isolate customer records behind segmented networks.

24×7 Insider-Threat Monitoring

Deploy behavioral analytics tools that flag unusual data exports, screenshotting, or off-hours access by frontline agents—even if they connect from approved workstations.

Real-Time Data-Leak Detection

Integrate dark web monitoring and breach-intelligence feeds to identify stolen client information quickly, enabling rapid customer notifications and credential resets.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

Phishing-Resilience Training

Offer continuous education and simulation campaigns so both vendor staff and end users can recognize and report social engineering attempts spawned by leaked records.

Incident-Response Playbooks

Maintain clear escalation paths that include vendors. Regular tabletop exercises should cover scenarios where outsourced employees become malicious insiders.

Post-Breach Remediation Guidance

After an exposure, MSPs can coordinate forced password rotations, enable or enforce multi-factor authentication, and assist with credit- or identity-protection services for affected users.

Also read: Everything you need to know about CDSL Malware attack

Contractual Security Clauses

Help clients renegotiate BPO agreements to include penalties for lapses, mandatory breach reporting within defined timelines, and explicit cybersecurity framework adherence (e.g., SOC 2 or ISO 27001).

By combining preventive controls with rapid detection and a vendor-inclusive response strategy, MSPs and MSSPs can turn the Coinbase incident into a blueprint for stronger, more resilient security across their customer base. To extend this service around the clock, Secucenter has its army ready to assist at all times.

Our SOC monitoring services are designed for MSSPs that offer a complete package of cybersecurity to their customers. We understand the importance of data and privacy, and thus, our proactive approach makes us fit in the cyber market to detect and deter threat actors.

Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

Fortinet has found itself at the center of an unauthorized access incident wherein the attackers have taken over full device control. The vulnerability detected in the OS was CVE-2025-22252(Missing Authentication for Critical Function) with a critical severity of 9.0 that allows an attacker knowledgeable of an existing admin account to access the device and bypass authentication.

It exists in FortiOS, FortiProxy, and FortiSwitchManager TACACS+ configured to use a remote TACACS+ server for authentication. After being discovered by Cam B from Vital and NBS Telecom’s Matheus, Fortinet quickly took action to prevent any further progress by the threat actor.

Under this threat, which products have been affected? Let’s find out.

As per the security advisory, three of the twelve products are affected. Here’s how they’ve summarized the effects and the action we can take.

Affected ProductsRemedy
FortiOS 7.6Upgrade to 7.6.1 or above
FortiOS 7.4 Through 7.4.6Upgrade to 7.4.7 or above
FortiProxy 7.6.0 Through 7.6.1Upgrade to 7.6.2 or above
FortiSwitchManager 7.2.5Upgrade to 7.2.6 or above

Also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

Fortinet has assured that the current vulnerability is limited to configurations that require ASCII authentication. PAP, MSCHAP, and CHAP configurations are safe from the impact. Additionally, Fortinet offers two workarounds that do not use ASCII authentication, which can prevent the vulnerability from impacting other devices. This aims towards organizations who may not be able to make the upgrade sooner.

Also read: Everything you need to know about CDSL Malware attack

As an experienced cyber expert, Secucenter has seen how large-scale cybersecurity companies and their products are targeted to access client data for many negative reasons. Staying secure is not a one-time thing, but a recurrent requirement that needs attention. If you are an MSSP, then our dedicated SOC services are here to provide that extra layer of protection to your clients from current and future threats.

A Critical Vulnerability Rating of 10/10 Has Been Confirmed By Microsoft

A critical vulnerability score of 10/10 is a very rare circumstance, and Microsoft seems to have caught itself in one of those.

Recently, Microsoft confirmed that its core cloud services were impacted by several critical vulnerabilities, one rated at 10, while the others were rated at 9.9 and 9.1, respectively. As users, what do you do in this situation? Well, nothing! That’s right; Microsoft has also confirmed all their users are protected from the vulnerability and their information is secured tightly.

So, what are these vulnerabilities, and how can we categorize their severity? Four of them were detected, and we can understand the scale they fall into.

CVE-2025-29813: Azure DevOps Elevation of Privilege Vulnerability 

Visual Studio has a significant elevation of privilege vulnerability triggered by inappropriate handling of pipeline job tokens.. It could allow an attacker with access to a project to swap a short-term token for a long-term one, thereby gaining extended access. With a CVSS score of 10.0, the vulnerability is exploitable over the network without requiring privileges or user interaction, and it poses a high risk to confidentiality, integrity, and availability.

CVE-2025-29972: Azure Storage Resource Provider Spoofing Vulnerability

A critical spoofing vulnerability involving Server-Side Request Forgery (SSRF) in Azure. It allows an authorized attacker with low privileges to send unauthorized requests over a network, potentially spoofing internal services. With a CVSS score of 9.9, the vulnerability is easy to exploit, requires no user interaction, and can significantly impact confidentiality, integrity, and availability.

Also read: Everything you need to know about CDSL Malware attack

CVE-2025-29827: Azure Automation Elevation of Privilege Vulnerability

A critical elevation of privilege vulnerability in Azure Automation was caused by improper authorization controls. It enables an attacker with low-level access to escalate their privileges over the network. With a CVSS score of 9.9, this vulnerability poses a high risk to confidentiality and integrity, with moderate impact on availability. It requires no user interaction and is low in complexity to exploit.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

CVE-2025-47733: Microsoft Power Apps Information Disclosure Vulnerability

This vulnerability ranges to a critical scale of 9.1 and allows an attacker to disclose information over the network. It is a high-severity information disclosure vulnerability in Microsoft Power Apps, stemming from a Server-Side Request Forgery (SSRF) issue.

Though this was a security concern for many individuals and businesses working with Microsoft cloud services, it proved the swiftness of Microsoft to immediately safeguard its customers. As a cybersecurity expert, Secucenter offers a second layer of cyber protection for every organization. We understand the importance of protecting important data from threat actors who are as advanced as the tools that are being invented. Thus, to ensure long-term operations, an organization can always utilize an additional layer of cybersecurity.

CISA Stepping In Aid Of CVE Then is The Gist 

The CISA has blazoned the continued civil backing for the CVE program,  icing the ongoing operation of a system that’s essential for global vulnerability shadowing. This development came amidst a heightened position of concern within the cybersecurity industry, following reports that the current contract with The MITRE Corporation is set to expire on April 16 without plans for renewal. 

CVE, managed by MITRE, serves as an encyclopedia with standardized IDs for given security vulnerabilities and support tools used by merchandisers, experimenters, and SOCs worldwide. MITRE has been receiving backing from the Department of Homeland Security’s National Cybersecurity Division. CVE supports multitudinous security tools,  fabrics, and protocols. 

The urgency around backing was amplified by MITRE Vice President Yosry Barsoum, who emphasized that a lapse in fiscal support would disrupt not only the CVE program but also the Common Weakness Enumeration ( CWE) action. Barsoum states that such a dislocation could affect vulnerability databases, software seller collaboration, automated discovery tools, and indeed public critical infrastructure defense systems. The warning emphasized the critical significance of foundational systems in the overall cybersecurity ecosystem. 

Also read: Coinbase Data Breach: Bribery Leads to USD 400 Million Loss

In a visionary response to the growing concern around centralized backing, members of the CVE Board recently announced the confirmation of the CVE Foundation, a nonprofit entity created to ensure the program’s long- term sustainability and global impartiality. The foundation, which has been in development for over a year, aims to reduce dependence on any single government guarantor by transitioning CVE to a more community- driven governance model. 

A statement from the founding group stressed the growing apprehension within the cybersecurity community regarding the future of such a pivotal system being reliant on a single point of backing. The program aims to enhance transparency, promote participatory responsibility, and adapt flexibly as it evolves to address arising global challenges. 

Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft

Meanwhile, other transnational players are taking steps to make similar systems that support global cyber adaptability. The European Union Agency for Cybersecurity ENISA) has launched the European Vulnerability Database EUVD), a cooperative platform that summarizes vulnerability data from a range of public sources. This reflects a broader trend toward distributed, multi-stakeholder approaches to cybersecurity infrastructure. 

As the global security terrain becomes decreasingly complex and distributed, security operations centers must be equipped to reuse, prioritize, and act on vulnerability data with speed and precision. This is where Secucenter delivers real value through their moxie. Secucenter’s advanced SOC capabilities enable real- time  sapience, contextual  trouble discovery, and  nippy response, helping associations transform critical vulnerability data into decisive action

Zero-Day Attacks On Firewalls: Fortinet Issues Warning

Fortinet issues a warning on a new Zero-Day attack on Fortinet FortiGate firewall devices with management interfaces exposed to the public. The campaign began around mid-November 2024 by accessing management interfaces, creating new admin accounts, changing configurations, and bypassing SSL VPN for lateral movement. The threat actors are unknown, and they have taken advantage of this vulnerability to extract credentials using DCSync.

For context, a Zero-Day is an unknown software vulnerability exploited by hackers to gain entry into vulnerable networks, servers, and systems. It is called Zero-Day because it occurs before an organization becomes aware of it, giving them zero days to address the issue.

The firmware devices that were impacted and are still undergoing recovery range between 7.0.14 and 7.0.16, which were released in February and October of 2024.

Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft

Fortinet has confirmed that the attacks came in four waves:

  • Scanning and reconnaissance.
  • Configuration changes (e.g., enabling new admin accounts).
  • Creating local user accounts with VPN access.
  • Credential extraction for lateral movement.

Currently, Fortinet has given its response to update its firmware and minimize public-facing interfaces to control future threats.

Simply put, a fault in a firewall was used to gain bigger access, create an entryway for hackers, and move deeper into their networks. As a SOC service provider, we’d agree no security is too much security. If you harbor confidential data that can put an entire organization or a chain of clients at risk, then having 24/7 SOC monitoring can save you potentially costly losses and lawsuits.

Volkswagen Group’s Data Breach Exposed Over 800,000 EV Customers’ Information

The mere thought that our personal information from a car company’s database can be spooky enough, let alone it happening eight hundred thousand times. However, this is the scenario of Volkswagen Group, whose data breach and poor configuration of data resulted in the exposure of over 800,000 EV customers’ information.

According to Chaos Computer Club, the data remained in the publicly accessible platform for months. This breach showed the precise GPS location of its users and contact information. Volkswagen’s software subsidiary, Cariad, contained accurate personal data that was synced with Amazon’s cloud facility but poorly configured. This gap left a loophole for free access to private customer information. The vulnerable customers included ordinary people, high-profile executives, and government workers who faced malicious risks if not reported.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

The pattern of data breaches is not limited to Volkswagen. Kia was also informed about a similar security flaw that could have compromised the personal information of millions. Ferrari, BMW, and Porsche are more brands that have come under intense public scrutiny due to their inadequate customer security systems.

This breach shed light on the reliability of data privacy in the automotive sector. As a SOC service provider, Secucenter finds the need to protect data and information across platforms and sectors with not just one but multiple cybersecurity shields.

Major Data Breach At Cisco: Intel Broker Steals 4.5 TB Of Value Data

The hacker group “Intel Broker” has successfully breached Cisco’s network, allegedly claiming to have exfiltrated approximately 4.5TB of sensitive data tied to various Cisco products. The breach reportedly occurred after Cisco inadvertently left its DevHub instance exposed, granting unauthorized access to critical systems.

Threat actors identified as “@zjj,” “@IntelBroker,” and “@EnergyWeaponUser” are said to have exploited this vulnerability, downloading sensitive files and sighting poor security at major institutions. IntelBroker has since claimed responsibility for the breach and the hackers are alleged to offer the data for sale on the dark web.

The exposed data includes proprietary Cisco products such as

Cisco C9800-SW-iosxe-wlc.16.11.01,

Cisco IOS XE & XR,

Cisco Identity Services Engine (ISE),

Cisco Secure Access Service Edge (SASE),

Cisco Umbrella, and

Cisco Webex.

Hackers have shared some files with the cybersecurity community to validate their claims and attract buyers for a purported “full version” of the stolen data.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

If the breach is confirmed, it could lead to serious implications for Cisco’s business. Proprietary software and platforms like Webex and Umbrella may face exploitation risks, while organizations relying on these products could encounter vulnerabilities. Cybersecurity experts are urging users of Cisco technologies to remain vigilant and monitor for security updates or patches. Cisco has not yet commented publicly on the breach, leaving the industry closely monitoring its response and future security measures.

When it comes to cybersecurity, one shouldn’t blink at the possibility of a hack. Targeted attacks such as these not only affect the organization itself but also its clients in extension. There are multiple ways to keep your data secure, but Secucenter offers you a more concentrated solution called SOC monitoring. Our SOC engineers will be proactive in monitoring your systems and endpoints for unusual activities and report in case it is detected. This has been beneficial for businesses, allowing them to clock out or take a break without worrying about exposing their confidential information.

Deloitte Compromised and Data Confiscated: Brain Ciper Ransomware Allegedly Stole 1TB Of Data

Deloitte, one of the Big Four accounting firms, has found itself in a predicament. On December 4th, reports revealed that the ransomware group Brain Cipher breached Deloitte UK’s systems, stealing up to one terabyte of data and digital materials. The infamous group emerged in June 2024 and gained notoriety for invading Indonesia’s National Data Center, which disrupted 200 government institutions.

Brain Cipher, alleging infiltration, has challenged Deloitte with threats to release confidential information such as security protocol violations, analyses of contractual agreements, details about monitoring systems and security tools, and examples of compromised data. They have invited Deloitte UK representatives to a negotiation; however, Deloitte has not directly confirmed or denied this incident.

Also Read: A Critical Vulnerability Rating 10/10 Has Been Confirmed By Microsoft

Despite strong security measures, hackers still find ways to breach your systems and steal sensitive data to use against you. Breaches like this expose the need to employ cybersecurity that completely protects your business and clients. This breach could impact Deloitte UK’s clients, confidential business data, financial records, and its professional reputation.

As cyber threats evolve, the need to consider proactive cyber protection approaches makes it an inevitable tool. SOC solutions proactively identify vulnerabilities, ensure regulatory compliance, and protect against evolving threats, all while being cost-effective. Secucenter welcomes you to explore the benefits and reasons to utilize our SOC solutions for that extra layer of safety.

Protect Your Business Today To Scale Tomorrow

Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.

Phone

+1 607 360 5504

Sales Office - United States

651, N Broad St, Middletown
Delaware-19709

Operations Center- India

Level 17, TransAsia Cyber Park
Kochi, Kerala-682030

Data privacy notice. All submissions are protected via TLS 1.3 encryption in transit and processed within our secure, air-gapped data environment. We never resell your data.