# Triple X claims Bank of Baroda data leak

Published: 2026-07-24 · Severity: high · Sectors: financial-services
Canonical: https://vorant.io/reports/34e56483-712e-52a9-98c3-fceae913184b/triple-x-claims-bank-of-baroda-data-leak

> A ransomware group calling itself Triple X claims to be selling 1TB of Bank of Baroda customer data, including IDs and photos from account opening forms.

A listing on a ransomware leak site attributes a claimed breach of Bank of Baroda, India's largest public sector bank, to a group identifying itself as Triple X. The post asserts that roughly 100,000 to 300,000 customer account-opening forms were exposed, including personal banking, NetBanking, loan, NRI, and corporate banking records, along with photographs and national ID documents submitted during onboarding. The actor attributes the exposure to weak password practices at the bank and offers sample images alongside a full download link, framing the leak as a warning about downstream fraud risk to affected customers.

No technical details about the intrusion vector, malware used, or ransomware encryption are provided in the listing, and the claim has not been independently verified. The nature of the data described — government ID copies, photographs, and account forms — poses a significant identity-fraud and social-engineering risk if genuine, given the scale of a major national bank's retail customer base. As with many leak-site postings, the entry may represent extortion pressure rather than a fully verified breach, but the sensitivity of the alleged data and the bank's scale warrant treatment as a credible and high-impact claim pending confirmation.

## Mentioned in this report

- Threat actors: Triple X

Source reporting: https://www.ransomware.live/id/QmFuayBvZiBCYXJvZGEgYmlnZXN0IGluZGlhbiBiYW5rIGJhbmtvZmJhcm9kYS5iYW5rLmluQFRyaXBsZSBY

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/34e56483-712e-52a9-98c3-fceae913184b/triple-x-claims-bank-of-baroda-data-leak.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
