8 hours ago
- TripleX ransomware group breached Bank of Baroda via a compromised employee email account, exfiltrating 1 TB of sensitive data.
- The leaked data includes customer PII (Aadhaar, PAN, photos), financial records, audit reports, and loan documents, posing identity theft risks.
- The attack likely involved phishing, MFA bypass (e.g., AiTM phishing), OAuth abuse, or endpoint compromise, exploiting excessive permissions.
- Five technical scenarios explain how a single mailbox led to massive data exfiltration, including session token theft and cloud collaboration pivoting.