It is unfortunate that a massive personal data breach has been reported at Bank of Baroda resulting in the compromise of the personal data of many customers. It is said that over 1TB of data has been posted on dark web and it was compromised through an email of one employee. The leaked data includes Aadhaar information also making it a highly harmful information leak.
Had the Data Protection Board was in place and DPDPA 2023 was effective, this should have resulted in more than Rs 250 crores of penalty. Fortunately in the current scenario only CERT In can act under ITA 2000 and impose a penalty of upto Rs 1 crore. The customers can however file an individual/collective legal action for damages under Section 46 of ITA 2000 or through a writ petition at a High Court.
This is indicative of the failure of the information security system in Banks in general and if not addressed promptly, could lead to repetition in other Banks.
It would be interesting to observe how other banks respond to this threat. As some body looking at DGPSI-Banks as a DPDPA compliance framework, we would be watching the event closely.
We can continue the debate with ..What is the value of such data if BOB has to buy it back from the hacker?
It is presumed that the number of data sets lost would be in the range of 1 million. Dark web may value it at a minimum of Rs 100 each. The value of data lost could therefore be in a conservative estimate equal to Rs 100 million or Rs 10 crores.
Naavi








