Site icon dbarta24.com

Personal Data of Bangladeshi Citizens Being Sold Online for Money

Bangladesh personal data including NID information, call records and mobile location reportedly being sold online

Dbarta24 Special Report – Personal information of Bangladeshi citizens, including National Identity Card details, mobile phone locations and call records, is reportedly being sold openly online for relatively small amounts of money, raising serious concerns over data security and accountability.

An investigation by data and investigative journalism platform Dismislab found hundreds of social media advertisements offering access to sensitive personal information.

The investigation also identified at least 10 active websites allegedly offering different categories of citizens’ data at fixed prices.

According to the investigation, a buyer can obtain an NID copy in around 17 minutes, a mobile phone’s latest location in about 16 minutes and several months of call records within a few hours.

NID Data Available Within Minutes

Dismislab reportedly conducted several transactions to verify whether the information being advertised was genuine.

With the consent of an individual involved in one test, the investigators provided a mobile number and paid Tk 500 in advance. An NID copy was delivered within approximately 17 minutes.

In another test, investigators paid Tk 150 after providing a voter’s number and date of birth and received what was described as an NID “server copy.”

The accuracy of the information was subsequently checked against the individuals concerned.

The data reportedly matched the original records. In one case, even the mother’s name that had been corrected on the NID about two months earlier appeared in the information supplied by the seller.

Call Records and Mobile Locations Also on Sale

The investigation found that call records could also be obtained through these online networks.

For one mobile number, investigators paid Tk 1,050 for three months of call records. The file reportedly arrived within around two and a half hours.

The last 20 numbers, call times and call types in the supplied records were compared with the person’s actual call history, and the information reportedly matched.

Another seller advertised the latest location of a mobile phone, along with the relevant cell tower, address and map location, for Tk 1,500. The information was reportedly delivered within 16 minutes after payment.

A Price List for Sensitive Information

The investigation identified websites offering a range of personal information at different prices.

Reported prices included Tk 50 to Tk 200 for an NID “server copy,” Tk 250 for obtaining NID information using a mobile number, Tk 900 for three months of call records, Tk 1,800 for six months of call records and Tk 1,500 for a person’s “live location.”

Information allegedly linked to mobile financial services was also advertised. A seller listed information related to Nagad accounts for Tk 7,000 and bKash-related information for Tk 7,500.

Other items reportedly offered for sale included birth registration records, the first page of passports, Taxpayer Identification Numbers (TIN), police clearance documents, land development tax receipts, SMS records and mobile device identification information.

How the Data Market Operates

The investigation suggests that the alleged data-selling network has developed a relatively organised structure.

Potential customers are reportedly approached through Facebook and other social media platforms. Intermediaries then place orders by depositing money with websites that allegedly supply the information.

Payments are reportedly collected through mobile financial services including bKash, Nagad, Rocket and Upay.

The information is then distributed to customers through platforms such as WhatsApp, Telegram and Facebook, sometimes at prices higher than the original purchase cost.

During a month-long investigation, Dismislab reportedly identified promotional activity involving at least 112 mobile numbers.

One Grameenphone number was found in 75 separate posts, while advertisements offering personal information appeared repeatedly in at least 36 active Facebook groups.

Questions Over the Source of the Data

The investigation also identified the operator of one website. The person reportedly works in mobile phone repair and claimed to obtain the information from another group.

However, the method allegedly used to access government servers, or the technical validity of the claim, could not be independently verified.

Information technology specialist Suman Ahmed Sabir said that when recently updated personal information becomes available almost instantly, it may indicate involvement by an insider at a relevant organisation or exploitation of a weakness in a database’s security.

The Problem Has Persisted for Years

The sale of personal information through online platforms is not a new phenomenon in Bangladesh. Advertisements offering NID and telephone information have reportedly been appearing on Facebook, Telegram and WhatsApp groups for several years.

A government-level investigation in 2024 reportedly found evidence of NID and call-record sales across 21 WhatsApp groups, 48 Telegram groups and 720 Facebook groups and pages—789 groups and pages in total. In some cases, the misuse of login credentials belonging to law enforcement personnel was also reportedly identified.

Despite these findings, the problem has continued.

The latest investigation indicates that the market has expanded rather than disappeared, with hundreds of advertisements and multiple active websites reportedly offering sensitive information in 2026.

Repeated Data Security Incidents

Concerns over personal data protection extend beyond online marketplaces.

Bangladesh has experienced a series of data-security incidents involving government databases, critical infrastructure, financial institutions and other organisations in recent years.

In 2023, a security weakness in a government birth and death registration website reportedly exposed information belonging to nearly 50 million citizens, including names, dates of birth, NID numbers and phone numbers.

The incident was reportedly linked to a technical vulnerability rather than a conventional hacking attack.

In 2024, several other cyber incidents involving government and critical infrastructure came to light.

Reports also emerged that root access to Titas Gas’s firewall had been offered for sale on the dark web, while a ransomware group claimed to have stolen large volumes of information from Popular Life Insurance.

The financial sector also faced security concerns. In one case involving City Bank, unauthorized access to limited customer financial information was reportedly detected, followed by attempts to sell the information. The bank said the access resulted from a system-related weakness.

Warnings over cyberattacks targeting Bangladesh’s banking sector and wider cyber infrastructure continued in 2025.

Reports of attempted intrusions and data theft involving important government databases also emerged, while government and defense-related systems continued to face cyber threats in 2026.

Millions of Job Seekers’ CVs Allegedly Offered for Sale

Another recent concern involves claims that the CVs of around six million Bangladeshi job seekers have been offered for sale online.

A hacker group reportedly claimed that the CVs were obtained from the database of a job website. The documents allegedly contain names, phone numbers, addresses, email addresses, educational qualifications, professional experience and training information.

The advertisement reportedly included 148 sample CVs. Most appeared to be old, with many last updated between 2011 and 2017. Some individuals whose CVs appeared in the samples reportedly confirmed that they had previously uploaded their resumes to the job website.

The organisation concerned, however, denied the allegation of a data breach.

Who Is Accountable?

The findings raise a broader question: how secure is citizens’ personal information once it enters government, financial, telecommunications or other institutional databases?

The investigation suggests that personal-data trading is no longer limited to isolated individuals. Social media platforms, websites, intermediaries, mobile financial services and rapid data-delivery systems appear to have become part of an ecosystem through which sensitive information can allegedly be obtained and redistributed.

Such combined information can potentially facilitate fraud, identity theft and targeted phishing attacks.

The recurring nature of these incidents also raises questions about enforcement. Despite repeated reports of NID and other personal-data leaks, there have been relatively few publicly known examples of perpetrators being brought to justice.

Protecting citizens’ personal information requires more than responding after a breach occurs.

Authorities and organizations need to identify where sensitive information is being accessed, how it is leaving secure systems and whether internal controls are being bypassed.

For Bangladesh, the growing online market for personal information highlights the need for stronger database security, effective monitoring, accountability and a coordinated response to data breaches.

Without addressing the source of the leaks, simply removing individual advertisements or websites is unlikely to solve the wider problem.

Exit mobile version