
RBI governor Sanjay Malhotra said large banks and regulated entities have strong IT systems, days after a reported breach at Bank of Baroda. Mint reported that about 1 terabyte of customer and…
RBI governor Sanjay Malhotra said large banks and regulated entities have strong IT systems, days after a reported breach at Bank of Baroda. Mint reported that about 1 terabyte of customer and internal data was exposed after an employee’s email account was compromised. The files reportedly included KYC records, loan documents, account details, audit reports and vigilance records. Bank of Baroda said its core business continued normally and that it was assessing the incident. Cyber investigator Ritesh Bhatia said the material circulating online could enable identity fraud and misuse of customer data, though the full scope of the breach is still under assessment.

Malhotra said the RBI regularly supervises banks and follows up on security gaps. In April, the central bank gave lenders two months to submit board-approved cybersecurity reviews and action plans, along with AI governance frameworks. Mint reported that no updates on these submissions were available. A BCG and Data Security Council of India report recorded over 4.93 lakh attacks and breaches targeting Indian banks in 2025.

The lazy narrative is that a breach proves Indian banks are unsafe, while the opposite claim that strong systems prevent serious harm is also too sweeping. Both security controls and employee access can fail, and the reported exposure includes documents that can aid fraud even if banking operations remain normal. The useful test is whether Bank of Baroda confirms what data was accessed, how many customers were affected, and whether the RBI’s required gap reviews led to fixes within the stated deadlines.
Sources (2): ciso.economictimes.indiatimes.com, livemint.com
This story was synthesised by AI from the 2 sources linked above.