Thursday, September 10, 2026

Bangladesh Personal Data Is Being Sold Online, Raising Serious Privacy and Security Concerns

Personal data belonging to Bangladeshi citizens—including national identity information, phone numbers, call records and location details—is reportedly being offered for sale online, raising concerns over privacy, identity fraud and the security of government and private databases.

Investigations have found advertisements on social media and other online platforms offering access to sensitive information in exchange for money. The data reportedly includes National ID (NID) records, call detail records (CDRs), mobile phone locations, SMS lists, birth-registration information, passports, tax identification numbers (TINs), IMEI details and mobile financial service records.

The scale and accessibility of the offers suggest that the issue may extend beyond isolated online scams. An investigation by Bangladeshi data and investigative journalism platform Dismislab identified 10 active websites allegedly involved in selling personal information, along with hundreds of advertisements posted across social media platforms.

An independent follow-up investigation based on the supplied information found that some sellers contacted through advertisements claimed they could provide NID records, call histories and mobile-location information for payment. Some of the information obtained during the investigation was also independently checked where verification was possible.

The findings indicate that at least some online sellers may have access to genuine personal information, although the source of that data remains unclear.

Data reportedly delivered within minutes

Dismislab reported that in one test, an NID PDF was provided 17 minutes after the investigators supplied a mobile phone number and paid 500 taka.

The document reportedly contained the individual’s name, photograph and date of birth, with the information matching the person concerned. Dismislab also reported that recently updated information appeared in the document.

In another test, investigators paid 1,050 taka for three months of call detail records associated with a phone number. The file was reportedly delivered about two and a half hours later.

According to Dismislab, recently contacted numbers, call times and call types in the file corresponded with the actual call history when checked.

In a separate test involving mobile-phone location data, information was reportedly supplied within 16 minutes of payment. The material allegedly included the most recent active time, a tower-based location, an address and a map location.

If genuine, such information could reveal not only who a person communicates with, but also when they communicate, for how long and where they are located.

Social media used to advertise sensitive information

The information appears to be marketed openly across several digital platforms, according to the investigations.

Advertisements and promotional posts have reportedly appeared on Facebook, Telegram, WhatsApp and dedicated websites, with sellers publicly seeking potential customers.

Dismislab said it identified 675 Facebook posts using a particular search term between June 15 and July 15. Of those, 605 posts contained offers to sell personal information.

The investigation also identified at least 112 different mobile phone numbers used for contact and found repeated advertisements in 36 active Facebook groups.

The findings raise the possibility that the activity involves more than individual sellers. The pattern could indicate an organised chain involving people who obtain data, intermediaries who find customers, payment arrangements and individuals who deliver the information.

However, the precise structure and scale of any such network would require further investigation.

Where is the data coming from?

The most critical unanswered question is the source of the information.

According to Dismislab, sellers gave different explanations about where they obtained the data. Some reportedly said they collected information from other groups or websites.

One seller allegedly claimed to obtain information from government servers through an API.

That claim could not be independently verified and therefore should not be treated as evidence of unauthorised access to government systems.

Nevertheless, the reported availability of apparently current personal information makes identifying the source of the data an urgent issue.

Investigators need to determine whether the information is being extracted from government or private databases, obtained through misuse of authorised access, acquired through compromised user accounts or credentials, or exposed through vulnerabilities in software and APIs.

The potential consequences go beyond privacy

The exposure of personal information can create risks far beyond the loss of privacy.

If identity documents, phone numbers, addresses, call records, location information and financial details are combined, they could potentially be used to construct a detailed digital profile of an individual.

Such information could facilitate identity theft, financial fraud, targeted phishing, harassment or unauthorised surveillance. Knowledge of a person's movements could also create risks to their physical safety.

For that reason, the issue is not simply about the unauthorised sale of data. It also concerns the potential misuse of information that citizens are required to provide to access essential services.

People routinely submit NID information when registering mobile SIM cards and provide identification and other personal details when opening bank accounts or using mobile financial services.

Personal information is also collected through passport, birth-registration, tax and land-related services.

Authorities need to trace the entire data chain

Closing individual websites or identifying individual sellers would not, by itself, address the underlying problem.

Authorities and relevant organisations need to determine how the information is obtained, who has access to it, how it is transferred and who ultimately receives it.

Financial transactions linked to the sale of personal data should also be examined where legally appropriate. Technical investigations could help establish which databases are being accessed, by whom and at what time.

Organisations handling sensitive citizen information should maintain reliable audit trails showing who accessed, downloaded or modified data.

Access to sensitive databases should be restricted according to users' roles and responsibilities, rather than being broadly available to employees or contractors. Stronger measures such as multi-factor authentication, role-based access controls, regular security audits and vulnerability testing can also help reduce the risk of unauthorised access.

Telecom sector faces particular scrutiny

The telecommunications sector requires especially strong safeguards because call records and location information can reveal highly sensitive details about an individual's activities and relationships.

Access to such information should be strictly controlled, with clear legal procedures governing when and under what circumstances it can be obtained.

Technical monitoring should also be capable of detecting unusual or unauthorised use of employee or authorised-user privileges.

Ultimately, personal information collected for public services or commercial transactions should not become a commodity in an uncontrolled online market.

The immediate challenge is therefore not only to identify those advertising the data, but to trace the information back to its original source and establish whether a security breach, misuse of authorised access, compromised credentials or another vulnerability is responsible.

A comprehensive investigation, combined with stronger technical controls and accountability for organisations that hold sensitive citizen data, will be essential to determine how widespread the problem is and prevent further unauthorised disclosure.

No comments:

How Just 30 Seconds Can Help Lift Your Mood

Feeling overwhelmed, anxious or mentally drained? Research suggests that improving your mood and easing everyday stress may not always requi...