When ransomware crews claim Indian fintech, we check
Leak-site claims are attacker marketing until independently verified. This is our running ledger of breach verifications against Indian financial infrastructure — what the attackers claim, what the company says, what the metadata actually shows, and where the stories diverge. Metadata-level only; no PII is republished, ever.
Bank of Baroda files published · investigation live
Triple X ransomware claimed 1 TB from India's second-largest public-sector bank on 24 July 2026. We completed a full crawl of the public Tor dump and verified it at metadata level: 162,111 files across 16,474 directories, ≈1.07 TB, with 1,088+ branches mapped by IFSC. The complete consumer investigation — branch search, explainer, vector analysis, censorship log — lives on its dedicated site.
Dodo Payments claim verified · dump unpublished
DireWolf named the merchant-of-record fintech on 15 August 2026, claiming 60.8 GB, 4 ClickHouse databases, ~39.3M rows (2025-05 → 2026-08). We verified the leak-site briefing over Tor and cross-checked it against Dodo's disclosure of a CVE-2026-72898 Metabase compromise the next day. The tension: the claimed inventory shape (CDC streams, prod + dev warehouses, Keycloak credentials) is broader than a "single internal reporting system" should hold. Download links are not yet live; our hourly watch is running.
We fetch leak sites over Tor, capture the attacker's own briefing, cross-check against company statements and third-party trackers (ransomware.live, SOCRadar, Breachsense), and analyse metadata only — file names, paths, table inventories. We do not download, republish or trade in stolen personal data. Numbers from leak sites are attacker-authored and marked as such until the underlying files can be independently examined. Every claim on these pages links to its source.