Bank of Baroda breach: verified & consumer-mapped
On 24 July 2026, the Triple X ransomware group claimed to have exfiltrated 1 TB from India's second-largest public-sector bank. We independently crawled the public Tor dump and verified the scale at metadata level. The complete, consumer-first investigation lives at bobbreach.cashlessconsumer.in — this page is the verification summary.
What we verified & how
| Lens | Method | What we can state |
|---|---|---|
| File count / volume | Completed crawl of the public Tor dump directory listing | 162,111 files across 16,474 directories, ≈1.07 TB in listed sizes — 0 crawl errors |
| Data types | File-name / path-pattern analysis | customer KYC, security reports, internal audit documents, branch references |
| Branch impact | Path references crossed against IFSC database | 1,088+ impacted branches mapped, searchable by IFSC |
| Threat actor | Triple X group dossier | timeline from May–July 2026, modus operandi |
This is metadata-level analysis of file names, paths and document types visible in the leak's directory structure — programmatically extracted, human-directed, cross-referenced. No LLM has access to actual file contents, and no PII from the dump is republished. Numbers are indicative. Independent verification is encouraged; full methodology is on the investigation site.
Beyond the summary
- Overview — what happened, what data was exposed, timeline, consumer protection guide
- Branch search — IFSC-based impact lookup for individual customers
- Eli5 / TL;DR — plain-language explainer
- Vector, demands, why — intrusion-vector and threat-actor analysis
- Censorship log — reports silenced for covering the breach
The verification and all related detail continue to be updated on the dedicated site.
Open bobbreach.cashlessconsumer.in