
Bank of Baroda Data Breach and India's Cybersecurity Framework
#GS-3 #Science & Technology #Cyber Security #Current Events #National #IT & Computers
Key takeaways
- Public sector lender Bank of Baroda launched a forensic probe after 1 TB of customer data was allegedly leaked onto the dark web.
- Financial institutions in India must mandatorily report severe cyber attacks to CERT-In within 6 hours of detection.
- Data privacy laws like the DPDP Act, 2023 and the IT Act, 2000 mandate strict legal penalties for institutions failing to protect personal user data.
Why in News
- Public sector lender Bank of Baroda started a forensic investigation after an alleged data breach exposed nearly 1 TB of customer information on the dark web.
- The bank clarified that its main core banking servers remain completely safe and uncompromised.
- Recent cyber incidents such as the Tata Electronics ransomware attack (2026), BSNL data breach (2024), WazirX crypto heist (2024), ICMR data leak (2023), and Air India cyberattack (2021) highlight growing gaps in India's cyber preparedness.
Understanding Layers of the Web
- The Surface Web includes all public websites that regular search engines can easily index and show to users.
- The Deep Web contains private online areas like personal email accounts, bank login portals, and internal corporate databases that require password access.
- The Dark Web forms a tiny, hidden section of the Deep Web that people can visit only using specialized software like the Tor browser.
- This hidden network masks user location and IP addresses, which turns it into a hub for trade in stolen data and cybercrimes.
India's Framework for Cyber Security and Data Protection
- CERT-In acts as the central national agency that manages major cyber threats like hacking attempts and phishing attacks.
- Financial organizations must report any critical cyber security incident to CERT-In within 6 hours of discovery.
- RBI's Cyber Security Framework for Banks requires every bank to maintain a board-approved policy, create a Cyber Crisis Management Plan (CCMP), and inform regulators about unusual incidents immediately.
- The Digital Personal Data Protection (DPDP) Act, 2023 forces entities like banks to protect personal user data or face heavy financial penalties.
- Section 43A and Section 66 of the IT Act, 2000 punish unauthorized system access and failure to safeguard sensitive personal information.