Bank of Baroda data breach: Is your money safe? Possible penalties and customer safety tips
New Delhi: Bank of Baroda has announced that it has been hacked by an employee who has used his personal email account to access some customer information. According to Reuters, its core banking system was not affected, and it has taken initial containment measures and has begun a forensic investigation into the matter.

The confirmation has turned focus on potential regulatory action, protections for customers and compensation that may be available to affected users. Customers should be cautious of the possibility of their personal details being used in phishing or identity fraud, but there is no evidence of any unauthorised banking transactions.
RBI, CERT-In and the DPDP Act could come under focus
The incident is expected to be investigated by the Reserve Bank of India (RBI), who will examine if Bank of Baroda met cybersecurity and risk management standards. If the central bank is able to conclude that the lender has violated the regulations, it could order the bank to take measures to improve its security system or punish the bank for the violation.
The cybersecurity agency for India, CERT-In, could also delve into whether the breach had been reported in time and whether the bank had adhered to the incident response protocols.
The case could also be picked up by the Digital Personal Data Protection (DPDP) Act, added Sudiptaa Paul Choudhury, Chief Marketing Officer of QNu Labs. The law calls for monetary penalties of up to Rs 250 crore for lack of reasonable security measures and Rs 200 crore for not disclosing a data breach, she said. Any regulatory measures will be based on the result of the current investigation, she added.
Is your money safe?
Bank of Baroda has claimed that its core banking system had not been breached. The incident reported is a data breach and not a breach of banking systems; no unauthorised fund transfer has been reported so far, Choudhury said.
She cautioned, however, that any information that’s out there can be used by scammers to set up a believable phishing attack. It is important for customers to be aware of calls, emails and messages from the bank being treated with caution.
What should customers do?
Expert advice is to change net banking and mobile banking passwords as soon as possible and have alert messages for transactions and avoid links sent or email. Only access banking services official app or website.
Choudhury also said that it is advisable for everyone to keep Aadhaar biometrics locked if there is any chance that the information in the Aadhaar has been leaked, to keep a check on the credit reports for any suspiciously high activity and to report any to the bank or the National Cyber Crime Reporting Portal. Customers can also call the cybercrime helpline 1930 to report fraud attempts.
