Back to Mumbai

BKC Police File FIR After Hackers Breach Bank Systems and Steal Over 1TB of Data

BKC Police File FIR After Hackers Breach Bank Systems and Steal Over 1TB of Data

The BKC police in Mumbai registered an FIR on August 28 against an unidentified person after the email account of a credit manager at a nationalised bank was compromised, leading to the alleged theft of confidential customer data from multiple branches across the country.

The security breach surfaced after the bank's Chief Information Security Officer, KR Ajaykumar, received a threatening email on July 9. The sender, identifying as the "Triple X" group, claimed to have infiltrated the bank's networks and downloaded more than one terabyte of data. The group warned that the stolen records would be made public unless the bank responded within a few days.

According to an officer from the BKC police station, the compromised files included account holders' re-KYC forms, mobile-number change forms, and a gold loan agreement, as well as personal data, financial records, and internal trade secrets.

The threat email was routed through the official account of Lalbahadur Khandwar, a credit manager posted at the bank's Mahilay branch in Gujarat. The email was copied to several senior officials and staff members. Nilesh Shah, a Hyderabad-based Deputy General Manager, contacted Khandwar about the message, but Khandwar denied sending it. An initial check revealed no corresponding records in his sent email folder.

Following the incident, Khandwar alerted branch manager Sunil Kumar and colleague Saurabh Sen, changed his login password, and escalated the matter to senior management. The bank subsequently blocked the compromised email account and launched an internal inquiry.

Police stated that the bank did not receive any ransom calls. The financial institution is working to retrieve the compromised data and has consulted cybersecurity experts to identify how the breach occurred and execute corrective measures. The BKC cyber police team is analyzing technical logs and attempting to trace the Internet Protocol (IP) address of the suspect. No arrests have been made so far.

Share

Related Stories