By Treacle Technologies
You’ve probably seen the headlines by now — one of India’s largest public sector banks confirmed a security incident after reports surfaced that close to a terabyte of sensitive data had turned up on the dark web: customer IDs, loan files, internal audit records.
The bank was quick to clarify that this wasn’t a breach of its core banking systems. It came down to one compromised employee email account. Nothing more dramatic than that.
And that’s actually what makes this worth talking about. Not the size of the leak, but the gap between “one mailbox got compromised” and “a terabyte of data ends up on a leak site.” How does that happen?
It’s rarely about how they got in
Most breaches don’t start with some brilliant zero-day exploit. They start with the boring stuff — a reused password, an account that never got MFA, someone clicking a link on a Tuesday afternoon while juggling six other things.
That’s probably what happened here too. The interesting part was never the entry point. It’s what came after.
Somehow, one mailbox held, or led to, an enormous amount of sensitive material: audit reports, loan appraisals, vigilance case files, customer identity documents. That’s a lot of exposure sitting behind a single login, and whatever happened next went unnoticed long enough for a large amount of data to walk out the door.
That’s the real story here. Not “someone got phished,” but “nobody noticed for a very long time.”
How one login turns into a terabyte-scale leak
The organization hasn’t disclosed the technical details of how this specific compromise unfolded, and we’re not going to speculate about it. But the broader pattern, mailbox compromise leading to large-scale data exposure, shows up again and again in breaches like this one, and it usually moves through a few recognizable stages.
It starts with initial access: a reused password, a missing MFA prompt, a phishing email that slips past the filters. Nothing exotic, just the everyday gap most security teams already know they have somewhere.
From there comes credential access. Once an attacker is inside a mailbox, they have time to look around, and inboxes tend to be full of things they shouldn’t be: saved passwords, VPN configs, password-reset trails that quietly point toward other systems.
That’s usually the doorway into lateral movement, using whatever credentials or session tokens they’ve picked up to reach file shares, document repositories, or other systems the compromised account had legitimate access to. Audit reports, loan appraisals, and vigilance case files don’t normally live inside someone’s inbox, so their presence in the leak points toward the attacker having reached further, into connected, networked storage.
And then exfiltration. Moving a terabyte of data out the door isn’t a single click, it’s bulk downloads or automated scraping sustained over time, the kind of activity that should look strange against someone’s normal usage pattern, if anyone happens to be watching for it.
Everyone tends to focus on that first stage, initial access. But the real damage, and the real opportunity to catch it, sits in what comes after.
This is exactly the gap deception technology is built for
Passwords, MFA, access controls, they’re essential, but they’re preventive. And preventive controls fail. Every security team knows this, even if nobody likes saying it out loud. Something eventually gets through.
So the better question isn’t “how do we stop every break-in,” because you won’t. It’s how fast you’ll know when one does.
That’s the problem deception technology exists to solve, and it’s what we work on every day at Treacle through our platform, i-Mirage.
Take a honeytoken — in Treacle’s platform, a honeycredential: a fake username and password buried in a config file, backup folder, or database script. Sitting inside that mailbox, it would have done one simple thing: fired the moment anyone tried to use it, because no real employee ever would. That covers the credential access stage directly, the exact point where an attacker starts turning one compromised inbox into a way to reach further.
A decoy asset works the same way for the next stage. A fake database, document repository, or admin portal, planted next to the real ones inside audit, credit, or vigilance systems, is built to get bumped into during lateral movement, the point where an attacker pivots from one compromised login toward whatever else it can reach.
And decoy documents — fake MoUs, contracts, or case files mixed in with the real audit records and loan files — make bulk exfiltration a lot harder to pull off quietly. In some setups they can even help trace where the data ended up. That covers the exfiltration stage too, the point where an incident goes from contained to a terabyte on the dark web.
None of this sits still, either. i-Mirage is AI-driven, so it watches how an attacker actually behaves at each stage, the pace of their reconnaissance, which credentials they try, how far they push into lateral movement, and reshapes the deception environment around them as they go, changing what’s exposed, how it responds, what gets revealed next. Alongside that, it runs a malware-capturing decoy that isolates and analyzes anything an attacker drops along the way. The goal isn’t just to catch the intrusion. It’s to keep the attacker engaged long enough to pull useful intelligence out of them before they realize something’s off.
None of this stops the initial compromise, to be clear. But it’s very good at catching what happens next, and in this case, what happened next is the whole story.
The takeaway
Breaches aren’t pass or fail. Most of them land somewhere in the middle, a small compromise that either stays small or turns into a headline, depending almost entirely on how quickly it gets caught.
Good authentication and clean data hygiene lower your odds of getting hit in the first place. Deception technology shortens how long an attacker gets to roam once they’re already in. In a case like this one, that window, the time between “they got in” and “someone finally noticed,” is where all the real damage happens.
That’s the problem we spend our time on at Treacle: giving security teams a signal the moment someone touches something they shouldn’t, with next to no false positives. The goal was never “never get breached.” Nobody gets that guarantee. The goal is finding out in minutes instead of months.
Treacle Technologies builds i-Mirage, an AI-driven deception and response platform, honeypots, honeytokens, and decoy infrastructure designed to catch intrusions early and keep small incidents from becoming big ones. Reach out if you want to talk about where deception could fit into your stack.
