General awareness
The bank that linked strangers to your account
- Does strong security mean you are compliant?
- No. Encryption stops someone getting in from outside. It does nothing about someone already inside, already trusted, using that access for a purpose the person never agreed to.
- Who this affects
- Any organisation where staff have legitimate access to customer records and are measured on targets that access can help them hit.
- What to do about it
- Write down the purpose each system was given data for, then ask who inside can use it for something else, and what actually stops them.
For two years it did not look like a scandal from the inside. It looked like success.
Bank of Baroda built a mobile app, bob World, and wanted every customer on it. Branch staff got targets. Every sign up counted, every target hit meant a better appraisal. The app started winning awards.
The customers who did not fit the target
The problem was customers who did not fit. No smartphone. A number that had lapsed. Someone who never gave the bank a number at all. On paper they could not be onboarded. So staff attached a number anyway, a colleague's, a guard's, sometimes one picked at random just to get the activation counted. The customer never signed anything for this. Most never found out.
A number on a bank account is not decoration. It receives the OTP. It can approve a password reset. It can move money out through mobile banking. Once a stranger's number sat on someone else's account, that stranger held a key to a lock that was never theirs.
The scale of it
In one zone, investigators found close to 1,300 numbers each tied to between 30 and 100 accounts, nearly 62,000 accounts exposed by that trick in that zone alone. Nationwide the average was 47 accounts riding on a single number. An audit confirmed Rs 22 lakh withdrawn from 362 accounts by the bank's own agents, using exactly this access.
When first asked why one number sat on dozens of accounts, the bank denied it. One number, one user, that is how the system works, it said. It took whistleblower documents and outside reporting to force a different answer. The Reserve Bank of India eventually barred Bank of Baroda from adding new customers to bob World. Over 60 employees were suspended, eleven of them assistant general managers.
Nobody had to break in
Nobody broke into the bank's servers. Nobody had to. Everyone involved already had the access their job required, the KYC file, the account, the screen to change a registered number. They used it for a number on a dashboard, not for anything the customer had asked.
This is what "we encrypt our data" never covers. Encryption stops someone getting in from outside. It does nothing about someone already inside, already trusted, using that trust for a purpose the customer never agreed to.
Where the DPDP Act changes this
This is the gap India's DPDP Act is built to close. The Act turns on purpose. Under Section 4, personal data may be processed only for a lawful purpose, either one the person consented to or a listed legitimate use. Under Section 6, consent is limited to the specified purpose and to the data necessary for it. A number attached to an account to hit an app target is a second purpose nobody consented to.
And the Act places that on the bank, not the clerk. Section 8(1) makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary, for processing undertaken by it or on its behalf. bob World predates the Act coming into force. What it exposed is exactly what the law now names as a violation.
The question worth asking
If you bank in India, the question is not whether your bank is secure. It is who inside can touch your account today, and what actually stops them, other than good intentions, from doing something with it you never said yes to.
If you run an organisation, the same question points inward. Every team measured on a number has a reason to reach for data that was collected for something else. Access controls tell you who can reach a record. They do not tell you what that person is allowed to do with it once they have. That second question is the one the Act asks.
Where this comes from
- Section 4, DPDP Act 2023, processing only for a lawful purpose
- Section 6(1), consent limited to the specified purpose and to necessary data
- Section 8(1), the Data Fiduciary is responsible irrespective of any agreement to the contrary
- The bob World findings are drawn from published investigative reporting and the subsequent supervisory action by the Reserve Bank of India