Background of the Incident
Bank of Baroda, India's second-largest public sector bank, discovered an alleged data breach where customer-related data (~1 TB) was reportedly posted for sale on the dark web. The bank immediately:
- Initiated a forensic investigation
- Confirmed that core banking systems remain secure and uncompromised
- Activated incident response protocols
Understanding the Dark Web
The World Wide Web consists of three distinct layers:
| Layer | Description | Examples |
|---|---|---|
| Surface Web | Publicly accessible, indexed by search engines | News websites, blogs, e-commerce |
| Deep Web | Unindexed but legitimate; requires authentication | Banking portals, private emails, corporate databases |
| Dark Web | Intentionally hidden subset requiring special software (Tor browser) | Anonymous communication, illegal marketplaces |
The Dark Web anonymizes user traffic and IP addresses, making it a preferred platform for cybercrime, data trafficking, and illegal marketplaces.
Major Cyber Incidents in India (Timeline)
- 2021: Air India cyberattack
- 2023: ICMR data leak (dark web)
- 2024: BSNL data breach
- 2024: WazirX crypto heist
- 2026: Tata Electronics ransomware attack
- 2026: Bank of Baroda data breach
India's Cybersecurity and Data Protection Framework
CERT-In (Indian Computer Emergency Response Team)
- Nodal agency for cybersecurity threats (hacking, phishing)
- 6-hour mandatory reporting: Financial institutions must report severe cyber incidents within 6 hours of detection
- Established under IT Act, 2000
RBI's Cyber Security Framework for Banks
- Mandates board-approved cybersecurity policy
- Requires Cyber Crisis Management Plan (CCMP)
- Immediate reporting of unusual cyber incidents
- Regular audits and vulnerability assessments
Digital Personal Data Protection (DPDP) Act, 2023
- Imposes strict obligations on Data Fiduciaries (organizations collecting data)
- Reasonable security safeguards mandatory
- Heavy penalties for data breaches:
- Up to ₹250 crore for minor breaches
- Higher penalties for negligent handling
IT Act, 2000
- Section 43A: Penalizes failure to protect sensitive personal data
- Section 66: Penalizes unauthorized access to computer systems
- Provides legal recourse for victims of data theft
Significance for India
- Critical Information Infrastructure Protection: Banking sector is classified as Critical Infrastructure under the National Cyber Security Policy
- Public Trust: Repeated breaches erode confidence in digital banking
- Regulatory Response: Forces stronger enforcement of existing frameworks
- Need for Cyber Resilience: Focus shifting from prevention to rapid detection and recovery
Way Forward
- Strengthen multi-layer security architectures
- Enhance cyber hygiene awareness among employees and customers
- Regular penetration testing and security audits
- Strengthening public-private partnerships in cybersecurity
- Coordinated response mechanisms between banks, CERT-In, and regulatory bodies