Report
Instagram ReelScam warning@Keshav Bedi3 sources
True, but exaggerated

The underlying fact is supported, but the wording goes further than the record.

Why we say that

Bank of Baroda data breach is real and recent, but past "negligence" claims about a 5700 crore settlement are false.

Core facts on the dark web leak, compromised employee email, password change advice, and phishing risks are accurate. However, the reel wrongly blames Bank of Baroda for due diligence failure and fraud in the NMC Health case, which was a no-liability settlement.

What it leaves out

The NMC Health settlement was without admission of liability or wrongdoing by Bank of Baroda. The litigation was initiated against the bank by administrators of the collapsed healthcare group, not due to bank fraud or due diligence failure.

Reported 15 Aug 2026

Claims

4 true · 4 unchecked

  • True

    A hacker has posted Bank of Baroda data on the dark web containing personal banking records, corporate banking records, and customer photos from forms.

    What's actually true

    Recent reports confirm over 1TB of customer data including Aadhaar, PAN, KYC photos, loan documents, and internal files appeared on a dark web forum.

  • True

    Bank of Baroda attributed the breach to a compromised employee email account.

    What's actually true

    The bank and multiple reports state the incident involved a single employee's compromised email account, not core banking systems.

  • True

    Experts are advising Bank of Baroda customers to immediately change their mobile and internet banking passwords.

    What's actually true

    News outlets explicitly recommend resetting net banking and mobile passwords immediately in response to the leak.

  • True

    Customers should expect phishing attacks, fake OTPs, or messages pretending to be from Bank of Baroda.

    What's actually true

    Reports advise heightened vigilance against phishing, suspicious calls, messages, and unverified OTP requests following the breach.

  • Couldn't check

    This is not the first instance of negligence by Bank of Baroda.

    What's actually true

    The reel presents the current breach as another example of negligence, but provides no specific prior cyber incidents. The NMC case is addressed separately.

  • Couldn't check

    In a recent case involving a Middle East healthcare group, Bank of Baroda's due diligence failure led to fraud, resulting in ongoing cases in Abu Dhabi and the UK that were settled out of court by paying 5700 crore.

    What's actually true

    We couldn't verify this claim with a reliable source. Bank of Baroda paid ~₹5700 crore to settle NMC Health litigation without any admission of liability or wrongdoing. Reports do not describe due diligence failure, bank-led fraud, or the bank initiating fraud.

  • Couldn't check

    The 5700 crore settlement would impact deposits and profits from customer savings that the bank operates on.

    What's actually true

    No sources address financial impact on customer deposits or savings profits.

  • Couldn't check

    In 2023, Bank of Baroda's mobile banking app had issues where employees were pressured to link multiple numbers, leading to forced registrations; the RBI had to intervene to stop it.

    What's actually true

    No sources in the notes corroborate this specific 2023 incident.

The full story, from the sources

Following reports of the alleged leak, account holders have been advised to immediately change their mobile and net banking passwords, enable... [against phishing/fraud]. - Source (2026) Bank of Baroda... paid $600 million (about ₹5,700 crore) to settle litigation initiated by the administrators of NMC Health... arising from the collapse of UAE-based B.R. Shetty led healthcare giant in 2020... without any admission of liability or wrongdoing by Bank of Baroda. - The Hindu (2026-07-03) Customer data from India's state-run Bank of Baroda, along with internal documents, has been leaked on the dark web... The data appeared on a dark web site on Saturday night and was advertised as a cache containing more than 700 gigabytes of information. - Reuters (2026-07-27) the breach involved a single employee's email account rather than its main banking systems. - NDTV (2026-07-27) an employee's email account had been compromised, allowing unauthorized access to 'certain data'... customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum. - The Record (2026-07-28)

From reporting

How it's framed (2)
Urgency and fear appeal - Large yellow banner with all-caps 'IMMEDIATELY change your PASSWORD!' combined with direct address to viewers and warnings of dark web leak, phishing to create immediate panic.
Loaded language and accusation - Repeated emphasis on bank's 'लापरवाही' (negligence), 'पल्ला झाड़ दिया' (shirking responsibility), and rhetorical questions to portray the bank as reckless.
Sources (10)
[1]news report2026-07-27
Reuters

Customer data from India's state-run Bank of Baroda, along with internal documents, has been leaked on the dark web... The data appeared on a dark web site on Saturday night and was advertised as a cache containing more than 700 gigabytes of information.

[2]news report2026-07-29
The Hindu

over 1 TB of data, including personal Aadhaar details of customers, has been accessed in an unauthorised manner and posted on the dark web... critical data of the banks was leaked into darkweb.

[3]news report2026-07-30
Economic Times (CISO)

Bank of Baroda data is now on the dark web: PAN cards, Aadhaar, passport size photos, address proof, identity proof, loan documents... sensitive customer records, including Know Your Customer (KYC) documents... internal audit files.

[4]news report2026-07-28
The Record

an employee's email account had been compromised, allowing unauthorized access to 'certain data'... customer information, corporate banking records, internal emails, loan documents and audit files on a darknet forum.

[5]news report2026-07-30
Instagram (InfosecTrain)

1 TB of Bank of Baroda data on the dark web... may have originated from a compromised employee email account... exposed information includes: Aadhaar numbers, Phone numbers, Banking & loan records, NetBanking details... KYC documents, photos & IDs.

[6]news report2026-07-27
NDTV

the breach involved a single employee's email account rather than its main banking systems.

[7]news report2026-07-28
Economic Times

Reset your net banking and mobile banking passwords now... treat the leak as real until proven otherwise.

[8]news report2026
Unknown publisher

Following reports of the alleged leak, account holders have been advised to immediately change their mobile and net banking passwords, enable... [against phishing/fraud].

[9]news report2026-07-29
Threads (@hk_chronicle_)

Following the alleged Bank of Baroda data breach, customers are advised to stay vigilant against phishing and fraud... Ignore suspicious calls, messages, or emails claiming to be from the bank... Never share your OTP, PIN, passwords.

[10]news report2026-07-03
The Hindu

Bank of Baroda... paid $600 million (about ₹5,700 crore) to settle litigation initiated by the administrators of NMC Health... arising from the collapse of UAE-based B.R. Shetty led healthcare giant in 2020... without any admission of liability or wrongdoing by Bank of Baroda.

About this account
  • Keshav Bedi's content often uses alarmist framing on economic and banking topics to drive engagement.
Notes on this check (6)
  • Dropped 1 source(s) cited as both supporting and contradicting "In a recent case involving a Middle East healthcare group…".
  • Dropped 3 support citation(s) for "A hacker has posted Bank of Baroda data on the dark web c…" because the cited passages do not address the claim directly.
  • Dropped 2 support citation(s) for "Bank of Baroda attributed the breach to a compromised emp…" because the cited passages do not address the claim directly.
  • Dropped 1 support citation(s) for "Experts are advising Bank of Baroda customers to immediat…" because the cited passages do not address the claim directly.
  • Dropped 1 support citation(s) for "Customers should expect phishing attacks, fake OTPs, or m…" because the cited passages do not address the claim directly.
  • Dropped 1 support citation(s) for "In a recent case involving a Middle East healthcare group…" because the cited passages do not address the claim directly.

Checked against 3 sources · 15 Aug 2026

Help us improve

Was this analysis useful?

One tap helps us find what Blindspot should improve next.