According to the reported timeline, the breach appears to have begun on 12 May 2026, when intelligence tracking systems flagged the initial compromise. TripleX publicly claimed responsibility on their darkweb blog, publishing 1TB of Bank of Baroda customer and internal banking data alongside sample files and download links.
The entry vector appears to have been a weak password on one of the bank’s internet-facing systems. No sophisticated exploit or zero-day vulnerability has been reported — just username and password-based access that an attacker obtained, possibly through credential harvesting on a compromised employee device or through brute force on some service running on the exposed system.
Once inside, TripleX appears to have followed a pattern observed in its previous campaigns, slowly collecting and uploading confidential data over time. Here is the timeline:
- 12 May: Reported initial compromise, believed to involve weak credentials
- 24 July: Data published on Tor leak site
- 25 July: Spotted by threat tracking platforms
- 26 July: Public alarm raised by security researchers
- 27 July: Bank of Baroda begins investigating
Based on the reported timeline, the data appears to have been collected and exfiltrated over a period of nearly 2.5 months before the incident came to public attention.
TripleX is not new. In May 2026, they breached PT Bank Negara Indonesia (2TB of data). The same month, they targeted Law Offices (1.5TB). The month before, they had built their operational infrastructure and began systematic targeting. Their darkweb blog is being run on professional infrastructure: multiple leak sites for different victims, forum presence for negotiations, sample data publication to prove access, and clear extortion messaging.
What distinguishes TripleX from traditional ransomware groups is that they did not encrypt data (at least there are no publicly available reports). In short, files were not encrypted. Systems were not disrupted.
Instead, the group’s apparent focus was on quietly exfiltrating sensitive information before using it as leverage for extortion. While the attacker silently extracted gigabytes of sensitive data — customer account information, Aadhaar numbers, loan records, internal communications, branch audit files, photos of national ID cards submitted during account opening — the bank’s operations continued normally.
The extortion model is pure data-threat: publish this data to dark web markets, sell it to credential brokers, leak it piece by piece to maximise reputational damage and legal exposure unless the victim pays. No encryption to reverse. No systems to restore. No backup recovery option. The data is already gone, already catalogued, available for free download.
Advertisement
TripleX typically contacts victims through encrypted channels like direct emails to executives, messages on darknet forums, or through some other manner of anonymous communication, with payment demands and deadlines. Whether Bank of Baroda received such communication and refused to pay, or whether TripleX decided to publish regardless to maximise impact and prove operational capability is not known. If the group’s claims are accurate, the data is now publicly available through its leak site.
TripleX’s own blog describes the breach in their characteristically blunt terms: ‘due to the bank’s weak password and mistake, my personal data should be leaked, and fraudsters should use my resources to scam people.’ The message reflects the group’s claim that the compromise resulted from weak credentials on an internet-facing system. If confirmed through the ongoing investigation, the incident would underscore the importance of strong credential management and basic cyber hygiene.
This is where endpoint data loss prevention becomes critical infrastructure rather than optional security. Traditional defences, like firewalls, intrusion detection, and vulnerability scanning, may not always detect this type of attack. The attacker appears to have used valid credentials, allowing the activity to resemble legitimate user behaviour. Detecting such activity requires visibility into sensitive data movement, where it should and should not move.
Critically, if a proper, functional DLP system monitoring endpoint data movement had been in place, it may have increased the likelihood of detecting or restricting large-scale data exfiltration during the collection phase. The exfiltration phase, when data is being collected and moved to attacker-controlled infrastructure, is the only window when prevention is possible. Once TripleX had already extracted and published the data, no amount of incident response, ransom payment, or backup recovery could undo the exposure.
In short, a data loss prevention system blocking export of customer information could have helped detect or restrict the exfiltration during the collection phase. It remains unclear whether such controls were in place or operating effectively.
TripleX now operates across multiple sectors — banking, legal services, corporate entities — using the same vector repeatedly: weak passwords on internet-facing assets, months of silent collection, public extortion. They have demonstrated operational maturity, infrastructure investment, and consistent targeting discipline. They are not script-kiddies opportunistically grabbing whatever appears vulnerable. Their operations suggest a structured and systematic approach to targeting high-value organisations.
The long-term impact of the incident will depend on the findings of the investigation and the extent of the reported data exposure. If the group’s claims are accurate, millions of customer records — names, addresses, Aadhaar numbers, banking information, loan details, agreements — may now be in the public domain, increasing the risk of identity fraud and financial scams. And TripleX has already published this information. The exposure has occurred.
If the reported exposure is confirmed, affected customers should consider their personal information potentially compromised and take appropriate precautions. If confirmed, the reported use of weak credentials, the prolonged period of data collection, and the apparent lack of early detection highlight the importance of credential security, continuous monitoring, and data exfiltration controls.
For enterprises, the lesson is clear: preventing data exfiltration is becoming just as important as preventing system compromise. As data-extortion groups continue to evolve, organisations will need to strengthen credential security, continuously monitor sensitive data movement, and prepare for attacks that prioritise information theft over operational disruption.
The author is CEO and Managing Director of eScan. Views are personal.


