VORANT. Threat Intelligence Sign in Get the full feed

Triple X claims Bank of Baroda data leak

high threat financial-services

A ransomware group calling itself Triple X claims to be selling 1TB of Bank of Baroda customer data, including IDs and photos from account opening forms.

A listing on a ransomware leak site attributes a claimed breach of Bank of Baroda, India's largest public sector bank, to a group identifying itself as Triple X. The post asserts that roughly 100,000 to 300,000 customer account-opening forms were exposed, including personal banking, NetBanking, loan, NRI, and corporate banking records, along with photographs and national ID documents submitted during onboarding. The actor attributes the exposure to weak password practices at the bank and offers sample images alongside a full download link, framing the leak as a warning about downstream fraud risk to affected customers.

No technical details about the intrusion vector, malware used, or ransomware encryption are provided in the listing, and the claim has not been independently verified. The nature of the data described — government ID copies, photographs, and account forms — poses a significant identity-fraud and social-engineering risk if genuine, given the scale of a major national bank's retail customer base. As with many leak-site postings, the entry may represent extortion pressure rather than a fully verified breach, but the sensitivity of the alleged data and the bank's scale warrant treatment as a credible and high-impact claim pending confirmation.

Mentioned in this report

Threat actors Triple X

Source reporting: https://www.ransomware.live/id/QmFuayBvZiBCYXJvZGEgYmlnZXN0IGluZGlhbiBiYW5rIGJhbmtvZmJhcm9kYS5iYW5rLmluQFRyaXBsZSBY

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free