BoB Data Breach: An Examination of the Largest Corporate Cyberattacks in India
The purported Bank of Baroda attack comes after multiple significant hacks targeting Indian banks, telecom providers, manufacturers, airlines, and fintech companies.
New Delhi, India: Nearly one terabyte of data was allegedly released on the dark web, and the state-run Bank of Baroda (BoB) is looking into the suspected data breach.
Retail and corporate banking records, customer account and loan details, net banking records, non-resident Indian and corporate banking data, and branch and ATM information are among the purportedly hacked data.
According to the Mumbai-based lender, it has started a thorough forensic investigation into the event and is closely collaborating with the appropriate authorities in compliance with all applicable regulations.
The event is the most recent in a string of data leaks and cyberattacks that have affected Indian companies in recent years. Millions of customer records, private company data, and occasionally intellectual property have all been compromised by these attacks.

Here are a few of the most significant data breaches and cyberattacks that have affected Indian companies in recent years.
Tata Electronics (2026)
After ransomware organization World Leaks claimed to have stolen and leaked over 200,000 files, or more than 630 GB of data, from the company, Tata Electronics revealed a cybersecurity problem in June 2026.
Documents connected to Apple and Tesla, including engineering files, supplier and component information, manufacturing data, and material specifications, were among the purportedly pilfered data. Photographs of Apple’s unreleased iPhone 18 Pro model were reportedly made public by the leak.
The government is looking into the situation.
BSNL (2024)
In 2024, Bharat Sanchar Nigam Ltd (BSNL), a state-owned telecom provider, came under fire after a hacker allegedly gained access to about 278 GB of the company’s data and put it up for sale on a cybercrime forum.
The Indian Computer Emergency Response Team (CERT-In) had reported a potential attack and data breach at BSNL on May 20, 2024; the Center subsequently stated in a Lok Sabha reply.
Sensitive information about the telecom operator’s network and subscribers, including International Mobile Subscriber Identity numbers, SIM details, Home Location Register data, DP card data, and DP security key data, was allegedly included in the leaked dataset.
WazirX (2024)
In 2024, hackers allegedly stole over $230 million worth of consumers’ cryptocurrency holdings from WazirX, one of the biggest cryptocurrency exchanges in India. This was one of the nation’s greatest cyberattacks. Almost half of the platform’s reserves were made up of the pilfered assets.
The exchange briefly halted bitcoin and rupee withdrawals, citing the situation as a “force majeure” event outside its control.
One of WazirX’s multi-signature wallets was the target of a hack, according to the company’s initial inquiry. It suspected that the attacker had gained control of the wallet by manipulating the transaction payload.
An Indian cryptocurrency platform experienced one of its worst losses as a result of the hack.

boAt (2024)
The consumer electronics company BoIn 2024, the company came under fire after a hacker claimed to have exposed over 7.5 million clients’ personal information on the dark web.
Customer names, addresses, phone numbers, email addresses, and customer IDs were purportedly included in the dataset, which was apparently about 2 GB in size. On a hacking forum, it was allegedly put up for sale.
The business claimed it has started a thorough investigation after acknowledging claims of the incident. It also stated that protecting client data continued to be its top priority.
ICMR (2023)
In 2023, the personal data of over 815 million Indians was allegedly offered for sale on the dark web, putting the Indian Council of Medical Research (ICMR) at the center of one of the country’s largest purported data breaches.
Along with names, phone numbers, and addresses, the leaked dataset purportedly contained passport and Aadhaar information.
A multi-agency probe was initiated by the breach. Four people were later taken into custody by the Delhi Police in relation to the crime.
Air India (2021)
In 2021, Air India revealed that over 4.5 million customers’ personal information had been compromised due to a cyberattack.
Passenger names, passport information, ticket details, frequent-flyer information, and certain credit card information kept between August 2011 and February 2021 were all compromised.
According to the airline, its passenger service provider’s data was the focus of the attack. It made clear that the impacted servers did not save card verification value numbers.

MobiKwik (2021)
In 2021, the fintech startup MobiKwik faced criticism over allegations that 110 million members’ personal information had been compromised and shared online.
Payment card details, phone numbers, email addresses, and know-your-customer information were allegedly among the compromised data.
The Reserve Bank of India instructed the business to look into the purported breach and threatened to take regulatory action if security flaws were discovered. However, MobiKwik refuted claims that its systems had been breached.
About The Author:
Yogesh Naager is a content marketer who specializes in the cybersecurity and B2B space. Besides writing for the News4Hackers blogs, he also writes for brands including Craw Security, Bytecode Security, and NASSCOM.
Read More:
200 New CVEs Daily: The Challenge of Effective Patch Management