What can we learn from Bank of baroda Data Breach?

On July 27 a data breach was reported at Bank of Baroda. News papers reported that nearly 1 terabyte of Bank of Baroda data had been published on the darkweb. Security analysts who had examined the files stated that it contained customer names, photographs, Aadhaar details, account-opening forms and account information.

The wider dataset was reported to contain records linked to savings and current accounts, net banking users, non-resident Indian customers, corporate banking services, branches and ATMs.

It was also reported that Bank of Baroda has also reportedly submitted a preliminary notification under a cyber-insurance programme led by National Insurance, the Economic Times said.  The programme reportedly provides total cover of INR 7.5 billion ($78 million), although the value of any claim has not been established.

BOB also gave a “Data Breach Notice” to the public through a post in X

BOB considered this as a simple email compromise by an employee. So at best it is a security breach by an employee not that of the Bank.

But knowing that BOB is a Section 70 (ITA 2000) notified company, whether CERT In would be satisfied about the reply or conduct a detailed enquiry.

BOB also filed a report to the stock exchange stating as follows-

Now we also see the following X report

I am reminded of a film song “Naguvudo Aluvudo Neeve heli”. But we are also reminded of another motivational film song “aagadu endu kaikatti kulithare saagadu kelasvu munde” and look ahead for better days where we understand the implications of such data breaches.

No other comment is required.

Naavi

 

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.