What is Customer Data Worth to a Cybercriminal?

0
31
Customer data breaches are becoming banking's biggest cybersecurity challenge, says Bank of Baroda incident.
Customer data breaches are becoming banking's biggest cybersecurity challenge, says Bank of Baroda incident.

The alleged Bank of Baroda data leak highlights a troubling reality – stolen identities can become more valuable than stolen money.

A bank’s greatest responsibility has always been to protect its customers’ money. But in the digital age, the bigger question is whether banks are equally equipped to protect something that has become just as valuable, if not more so: customer data.

The alleged data leak involving Bank of Baroda has once again brought that question into sharp focus. According to reports, nearly 1TB of data linked to the public sector lender surfaced on the dark web. Cybersecurity researchers who examined samples claimed the leaked information included customer names, account details, Aadhaar information, loan documents and internal banking records. Bank of Baroda has since said the incident originated from a compromised employee email account and maintained that its core banking systems remain secure while a forensic investigation is underway.

For customers, the reassurance that their money remains safe is undoubtedly important. Yet it also reveals how our understanding of cybercrime has failed to keep pace with reality. Today’s cybercriminals are not always trying to empty bank accounts. Increasingly, they are trying to fill databases.

That is because data has become one of the most profitable commodities in the cyber economy. Unlike cash, stolen data doesn’t disappear after it is taken. It can be copied endlessly, traded across dark web marketplaces and repurposed for entirely different crimes. A customer’s identity can be sold multiple times to different buyers. Fragments of information from one breach are often stitched together with data from another, creating detailed digital profiles that fuel phishing campaigns, account takeovers, loan fraud, SIM-swap attacks and AI-generated impersonation scams.

The theft itself is often only the beginning.

In many ways, cybercriminals now think like investors. They are not chasing one transaction or one account balance. They are acquiring assets that continue generating value over time. A single dataset containing verified identities can be exploited repeatedly, making customer information far more lucrative than a one-time financial theft.

That shift fundamentally changes what banks are expected to protect. Financial institutions are no longer just custodians of deposits. They are custodians of identity. Every account opening, KYC verification, loan application and digital transaction adds another layer to a customer’s digital footprint. Collectively, banks hold some of the most comprehensive personal datasets in the country. Protecting those datasets is no longer a back-office technology function. It is central to maintaining public confidence in digital banking.

The Bank of Baroda incident also exposes a broader challenge facing the financial sector. India’s banking ecosystem has become one of the most digital in the world. UPI has transformed payments. Mobile banking has made financial services accessible around the clock. AI is beginning to reshape everything from customer service to fraud detection. Every one of these innovations has improved convenience. Every one has also expanded the volume of sensitive information that banks collect, process and store.

The result is an uncomfortable paradox. The more digital banking becomes, the more valuable customer data becomes to cybercriminals.

This is why cybersecurity can no longer be measured solely by whether systems remain operational after an attack. A bank may continue processing transactions without disruption, yet still face lasting consequences if customer information escapes into the cybercriminal ecosystem. Operational resilience is important, but data resilience is rapidly becoming just as critical.

The incident also arrives at a time when India is strengthening its approach to personal data protection. Regulatory frameworks such as the Digital Personal Data Protection Act are pushing organisations to become more accountable for the information they collect and manage. But compliance alone will not solve the problem. Banks need to rethink data governance from the ground up. They need to ask difficult questions about what data they retain, who has access to it, how long it is stored and whether every piece of information they collect is genuinely necessary.

Cybersecurity, after all, is no longer only about keeping attackers out. It is about limiting what they can access if they get in. There is another lesson that deserves equal attention. Cyber incidents are often discussed in terms of systems, vulnerabilities and technical controls. Customers, however, experience them very differently. They experience uncertainty. They wonder whether they should change passwords, monitor transactions, ignore unfamiliar calls or worry about identity theft years down the line. In other words, they lose something far more difficult to quantify than data. They lose confidence.

Trust has always been the foundation of banking. It cannot be restored through a software patch or a forensic report alone. It is rebuilt through transparency, accountability and a visible commitment to protecting customer information with the same seriousness as customer funds.

The Bank of Baroda investigation will eventually establish the scale and circumstances of the alleged breach. But regardless of its final findings, the incident has already delivered a lesson for the entire industry. In an era where identities can be bought and sold as easily as financial assets, banks are no longer judged only by how well they safeguard money. They are judged by how well they safeguard the people behind it. That may well become the defining challenge of digital banking in the years ahead.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.