One of India’s largest state-owned banks has reported a cybersecurity incident after a threat actor claimed to have stolen and published sensitive banking data.
Bank of Baroda said Monday that an employee’s email account had been compromised, allowing unauthorized access to “certain data.” The bank said it detected and contained the incident immediately and that its core banking systems were not accessed or affected. An investigation is ongoing.
The disclosure follows claims last week by multiple cybersecurity researchers tracking dark web activity that an unidentified hacker had breached the bank and leaked what it described as customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum.
The authenticity of the purportedly leaked data could not be independently verified. Bank of Baroda did not comment on the hackers’ claims or say whether any customer data had been exfiltrated. It also did not attribute the incident to any specific hacking group.
Researchers said the threat actor, operating under the name “leak-king-F,” advertised the data for sale on a popular darknet marketplace and directed prospective buyers to a Telegram channel.
This is the latest cyber incident affecting major financial institutions and companies across Asia.
Last week, Thailand’s Securities and Exchange Commission launched an investigation into a data breach at the Thailand Securities Depository (TSD) after hackers claimed to have stolen investor information. The stock exchange disclosed that attackers had compromised an investor portal and gained unauthorized access to customer data. TSD said its trading, settlement and depository systems were not affected.
Earlier this month, the ransomware and extortion group World Leaks published thousands of files it claimed were stolen from contractors working on India’s largest nuclear power project. India’s state-owned nuclear operator said the documents contained no information affecting the safety or security of the plant and appeared to have originated from a third-party company building conventional, non-nuclear infrastructure for new reactors.
Separately, World Leaks claimed responsibility for an attack on Tata Electronics, a key supplier to Apple, Tesla and Qualcomm. The group demanded a $1.5 million ransom before publishing what it said were confidential engineering documents after alleging that the company had refused to negotiate.
Recorded Future
Intelligence Cloud.
