Bank of Baroda Data Leak: Beyond the Email Compromise

The Indonesia Connection

When an emerging ransomware group first appears, it rarely makes global headlines. Its early victims often pass with little scrutiny outside threat intelligence circles. That appears to be the case with TripleX, a relatively new extortion group that surfaced in 2026. Before it was linked to the alleged 1 TB Bank of Baroda data leak, the group had already claimed responsibility for targeting PT Bank Negara Indonesia, hinting at an unusual preference for large financial institutions. While the earlier incident received limited public analysis, the Bank of Baroda breach has put TripleX firmly in the spotlight and raised important questions about how the group operates.

Over the past week, cybersecurity publications have extensively covered (here, here & here) the publicly known facts: a compromised employee email account, the alleged exfiltration of hundreds of gigabytes of sensitive banking data, and the publication of that data on TripleX's leak site.

These reports answer what happened, but they leave several technical questions unexplored.

  • How does the compromise of a single mailbox result in nearly a terabyte of sensitive data being exposed?

  • What made this attack different from conventional ransomware?

  • Is there more to what meets the eye?

  • What's the financial impact of this attack?

Incident Overview & Attack Vector

On July 27, 2026, Bank of Baroda officially acknowledged a cybersecurity incident  The bank confirmed that an employee’s email account was compromised, leading to unauthorized access to certain internal data .

Although the bank immediately implemented containment measures and affirmed that its core banking transactional systems (Finacle) remained secure and uncompromised, the incident highlights a critical failure in authorization and identity access governance.

Publicly available investigations indicated that the exfiltrated data likely originated from shared folders and collaborative document repositories accessible through the compromised employee's permissions. One plausible explanation is that the compromised identity possessed broad access to shared repositories, the attacker was able to reach and exfiltrate over 92,000 files across 9,783 directories. 

Bank of Baroda Data Leak - Raven investigation
Attack chain of Bank of Baroda & PT Bank

Scope of the Exfiltrated Data

The leaked dataset represents a substantial exposure of personally identifiable information (PII) and highly sensitive operational bank documentation. The leaked archive appears to contain the presence of the following records.

  • Customer application forms (estimated between 100,000 and 300,000 records) including customer photographs and identity documents.

  • Personally Identifiable Information such as Aadhaar numbers, Permanent Account Numbers (PAN), passport-size photographs, and proofs of address.

  • Operational financial documents, including savings/current account records, NetBanking user details, and loan-related applications .

  • Highly sensitive internal audit reports, branch-specific audit files, loan appraisal documents, vigilance investigation records, and internal spreadsheets containing bank operations intelligence.

Sample Data of Bank of Baroda Leak

These leaked dataset functions as a "ready-made KYC kit" that could be easily weaponized by downstream threat actors to conduct identity theft, fraudulent loan applications, SIM-swap attacks, or to construct highly targeted, AI-driven phishing campaigns. 

Threat Actor Profile and Dark Web Infrastructure

TripleX operates as a data-extortion collective rather than a traditional ransomware cartel that utilizes encryption payloads. Rather than rendering systems inoperable and demanding payment for decrypters, TripleX aims to exfiltrate bulk datasets silently and threaten public exposure.

In this specific campaign, the group made the entire dataset publicly available for free download, citing "weak passwords" and "security failings" at Bank of Baroda as their primary justification. 

The group has established a history of targeting major financial entities .In May 2026, TripleX successfully breached PT Bank Negara Indonesia (a state-owned Indonesian bank), exfiltrating approximately 2 TB of sensitive contracts, identity files, and internal documents, which were similarly published online.

Below are the key indicators of compromise (IoCs) representing the Tor-based network infrastructure used by TripleX to disseminate the exfiltrated datasets 

Indicator Type

Value

Context

Tor Domain (onion)

ojcmpbdncjo5dhaxxll44bq6to3kwqtoeraevgsjquhdtt4uv5l4igid[.]onion 

Primary TripleX Data Leak Site (DLS) 

Tor Domain (onion)

6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad[.]onion 

Secondary download/hosting mirror used for storing massive file repositories 

Mechanism of the Perimeter Bypass and Access

As per official reports initial entry was achieved via a potential Business Email Compromise (BEC) targeting a specific employee mailbox. The threat group TripleX likely obtained the credentials through phishing or by exploiting weak/reused passwords that were actively traded on cybercrime marketplaces.

  • The authenticated email session was used to pivot into associated internal cloud collaboration platforms (likely Microsoft SharePoint and internal file-sharing servers) .

  • Because of excessive access permissions (standing group memberships that were never revoked), the single compromised mailbox was authorized to view and download historical documentation from shared folders used across various regional branches, audit divisions, and vigilance departments

  • Using automated command-line scripts or built-in sync features, the threat actors quietly harvested and exfiltrated approximately 1 TB of files directly over standard encrypted communication protocols (such as HTTPS/TLS), blending their malicious download traffic with normal business activity until it was compiled and released

Unlike Ransomware-as-a-Service (RaaS) operations that package DIY templates or buy automated kits, TripleX functions as a focused, hands-on data-extortion cartel that leverages specific, tailored social engineering methodologies to facilitate their own intrusions.

How Could a Single Employee Account Lead to a 1 TB Data Leak?

At the time of writing, the exact intrusion path has not been publicly disclosed. Bank of Baroda has confirmed the compromise of an employee email account, but the forensic investigation remains ongoing. That leaves an important question unanswered:

How does a compromised mailbox translate into nearly a terabyte of sensitive enterprise data?

Based on publicly available information and common attack techniques observed across Microsoft 365 and Google Workspace environments, several technically plausible scenarios emerge.

Scenario 1: The Simplest Explanation – No MFA

This is the scenario widely discussed across news reports.

Employee receives phishing email
│
Credentials harvested
│
No MFA challenge
│
Attacker logs into Outlook
│
Mailbox access
│
SharePoint / OneDrive discovery
│
Data download

While technically possible, for a large public sector bank operating under stringent regulatory expectations, complete absence of MFA for an internet-facing employee account would represent a significant identity security gap. Until official forensic findings are published, this explanation should be treated cautiously.

Scenario 2: AiTM Phishing (Most Common Modern Technique)

The attacker doesn't bypass MFA. They steal the authenticated session.

Employee clicks phishing link
│
Reverse proxy login page
│
Employee completes MFA
│
Session cookie captured
│
Attacker replays session
│
Microsoft believes user is authenticated

From Microsoft's perspective:

✓ Valid credentials

✓ Valid MFA

✓ Valid session

The attacker simply inherits the authenticated identity.

This technique has become increasingly common because it defeats organizations that believe MFA alone eliminates phishing risk.

No password.

No phishing login.

No MFA bypass.

Employee receives
"App requires permissions"
│
User clicks Accept
│
Malicious OAuth application
receives Graph permissions
│
Mailbox access
| 
SharePoint access
|
OneDrive access

To security tools, this often appears as a legitimate application operating with user-approved permissions.

Scenario 4: Endpoint Compromise

The employee device, not the identity - is compromised.

Malicious attachment
or Android malware
or infostealer
│
Browser cookies stolen
│
Session tokens extracted
│
Attacker imports cookies
│
Authenticated cloud access

Again, MFA offers little protection because authentication has already occurred on the trusted device.

Scenario 5: Business Email Compromise Escalates into Cloud Data Theft

The mailbox itself may not have contained a terabyte of data. The mailbox may simply have been the key.

Compromised mailbox
│
Search historical emails
│
Find SharePoint links
│
Locate Teams conversations
│
Access OneDrive
│
Access internal portals
│
Enumerate document libraries
│
Bulk download

Email becomes the organization's directory service.

Every project.

Every document.

Every shared folder.

Every approval.

Every business relationship.

One compromised identity can rapidly map an organization's entire information landscape.

Which Scenario Is Most Likely?

At this stage, nobody outside the official investigation knows.

The actual intrusion may involve one or a combination of these techniques.

The important lesson is that all five scenarios result in the same outcome:

  • A legitimate authenticated identity

  • Legitimate Microsoft or Google cloud traffic

  • Possible Graph API usage

  • Large-scale access to sensitive enterprise data

From the perspective of many traditional email gateways, nothing appears overtly malicious after authentication succeeds.

Plausible Downstream Threat Activity

One question naturally follows any large-scale banking data breach:

Will the data be used for follow-on attacks?

To answer that, we analyzed publicly available malware samples, phishing infrastructure, and command-and-control indicators using VirusTotal and other OSINT sources.

While there is insufficient evidence to attribute all Bank of Baroda-themed malware to the TripleX campaign, the timeline does reveal several interesting observations.

Rather than treating these artifacts as a single campaign, we categorize them based on their temporal proximity to the breach.

Bank of Baroda Data Leak

1. Activity Closely Aligned with the Breach Timeline

Two Android banking malware samples were first observed in June 2026, shortly before the public disclosure of the Bank of Baroda breach.

Sample

First Observed

Theme

BANK OF BARODA VERIFICATION-2.Bin

29 June 2026

Fake verification utility

Bank of Baroda KYC Update.apk

21 June 2026

Urgent KYC update

One of these samples communicates with a Firebase backend that became active in April 2026, suggesting supporting infrastructure was established before the malware was submitted.

Infrastructure

First Observed

Purpose

bob-tiger--apr26-default-rtdb.firebaseio.com

26 April 2026

Firebase C2 for credential and SMS collection

Why this is interesting

These dates fall within weeks of the reported compromise window.

While this does not prove operational linkage, it raises a reasonable hypothesis that threat actors were preparing or adapting mobile banking lures around the same period.

For defenders, these artifacts deserve priority investigation because they overlap with the known breach timeline.

2. Historical Brand Abuse

We also identified multiple older phishing and malware samples abusing the Bank of Baroda brand.

First Observed

Artifact

Theme

November 2023

Fake Fixed Deposit portal

Credential harvesting

September 2025

Aadhaar Update APK

Customer verification

November 2025

Bank of Baroda KYC.apk

Identity verification

January 2026

Pension Card APK

Pension customers

These samples clearly demonstrate that Bank of Baroda has been an attractive phishing brand for several years.

This is not unique.

Most major banks accumulate a large ecosystem of malware, fake applications, and credential harvesting pages that are continually recycled by different criminal groups.

Therefore, these historical artifacts should not be interpreted as evidence of the TripleX campaign.

Instead, they provide important context: attackers already had mature social engineering templates capable of impersonating the bank long before the 2026 breach.

  1. Harvesting the Target List: TripleX exfiltrates 1 TB of unstructured data containing over 100,000 sensitive customer KYC files (complete with phone numbers, emails, names, and loan accounts) .

  2. The Panic Lure: Utilizing this stolen contact database, the actors launch highly targeted SMS/email campaigns to the exposed victims. Because the victims are aware of the widely publicized Bank of Baroda breach , they are in a state of high anxiety regarding their account security.

  3. The "Security/Verification" Trap: Scammers exploit this fear by sending messages urging victims to "secure their profiles" or "verify their identity" by downloading the official-looking security patch BANK OF BARODA VERIFICATION-2.Bin 

  4. Credential & Fund Theft: Once installed, this Trojan connects to bob-tiger--apr26-default-rtdb.firebaseio.com to intercept incoming SMS OTPs and harvest mobile banking credentials, draining the retail accounts of the already-impacted breach victims 

Analysis of TripleX Motives

Unlike traditional ransomware syndicates that maintain strict private negotiations in hopes of securing a payout, TripleX operates under a hybrid model of financial extortion combined with ideological reputation-building.

  1. Retaliatory and Vigilante Extortion
    During the Bank of Baroda breach, TripleX publicly stated that the release of the ~1 TB dataset was a direct consequence of the bank's "poor security posture and lack of updates" . The group frequently adopts a "hacktivist-adjacent" persona, claiming to expose systemic vulnerabilities in state-owned banking systems to warn customers . This vigilante framing is used to justify the complete leakage of sensitive datasets without offering the victim an option to purchase confidentiality.

  1. Underground Market Monetization
    While they released Bank of Baroda's files publicly for free, their deep integration with high-profile hacking communities like Exploit[.]in suggests they monetize their access through secondary means 

    Access Brokerage: Threat actors often auction off high-privilege corporate credentials or active sessions on underground forums. 

    Strategic Stolen Data Sales: High-value elements of their exfiltrated datasets - such as personal identity indicators (KYC documents, PAN, Aadhaar) and internal system architecture details - are likely segmented and sold to financial fraudsters or secondary actors before the bulk unstructured data is dumped on their Tor leak site.

  2. Brand Elevation
    By target-locking massive financial institutions (such as Bank Negara Indonesia and Bank of Baroda) , TripleX rapidly establishes brand authority within the cybercrime ecosystem. Documenting proof-of-compromise screenshots directly on forums elevates their profile , allowing them to command higher premiums for future operations, partnerships, or access broker campaigns.

  1. Stock Market Manipulation Angle

     Bank of baroda stock.png
    Stock movement of Bank of Baroda

One hypothesis worth considering the market manipulation could be another operational motive.

Following their late-June 2026 email compromise , threat actors or affiliated financial networks possibly capitalized on extreme information asymmetry by executing an aggressive short build-up on July 3, 2026 - marked by an anomalous 15.02% single-day spike in Open Interest as the stock dropped to ₹251.80. While the group silently exfiltrated a 1 TB customer database, bearish option writers kept a tight lid on the stock throughout mid-July with a Put-Call Ratio of 0.71–0.77.

The trap was sprung during the public disclosure window (July 24 to July 28), when the leak on Ransomware.live and subsequent bank confirmation triggered an immediate market panic, plunging the stock to ₹239.20.

The Raven Perspective

The Bank of Baroda incident reinforces a broader shift that we're seeing across the industry.

Attackers are increasingly bypassing hardened infrastructure in favor of trusted identities. Once authenticated, they leverage legitimate cloud services, business applications, and collaboration platforms to access sensitive information without deploying sophisticated malware.

This is why the next generation of email security cannot be limited to filtering malicious messages before delivery. It must continuously evaluate identity, intent, context, and data movement throughout the lifecycle of an email interaction.

At Raven, we believe the future of banking security lies in answering questions that traditional email security products were never designed to ask:

  • Is this employee behaving like themselves?

  • Does this email request align with established business context?

  • Is this data movement normal for this user and department?

  • Is this communication building trust or abusing it?

Modern attacks don't begin with malware. They begin with trust. And defending against them requires security systems that understand trust as deeply as attackers do.

Part 2 coming in on What CISOs & Security leaders needs to do


Disclaimer: This analysis is based entirely on publicly available information, including official statements, open-source intelligence (OSINT), threat intelligence reports, cybersecurity research, and publicly accessible leak-site observations available at the time of writing. The technical analysis and attack reconstruction presented in this article represent our interpretation of the available evidence and are intended solely to help the cybersecurity community understand emerging attack techniques, improve defensive strategies, and encourage informed discussion. References to threat actors reflect public claims made by those actors or observations from publicly available threat intelligence sources and should not be interpreted as formal attribution.We do not claim access to non-public investigative findings, and certain aspects of the attack may evolve as additional information becomes available.

Sign-up for a trial

Go live in minutes