Muhammad Shah Alam – Four police constables in Dhaka have been arrested for allegedly using official government email accounts and forged legal documents to extract and sell citizens’ sensitive personal data to unauthorized third-party groups, law enforcement officials confirmed.
The arrested officers—identified as Constable Jihad Mia of Turag Police Station, Constables Saimum Hossain Rashed and Masum Mia of Demra Police Station, and Constable Nizam Uddin of Wari Police Station—were booked on September 29 under Sections 420, 409, and 109 of the Penal Code, as well as the Official Secrets Act. The Cyber and Special Crime Division of the Dhaka Metropolitan Police (DMP) Detective Branch is currently investigating the breach.
Fraudulent GDs and Case Records Used to Harvest Data
According to the First Information Report (FIR), the perpetrators compromised official channels to request sensitive Call Detail Records (CDRs), National Identity (NID) details, mobile SIM locations, SMS logs, and passport details.
On September 1, a request was submitted via the official email address of the Turag Police Station Officer-in-Charge (OC), requesting three months’ worth of CDRs for 11 mobile numbers under the guise of a General Diary (GD) filed on July 13. A subsequent internal probe revealed that no such GD existed. Constable Jihad Mia allegedly used Assistant Sub-Inspector (ASI) Shahinul Kabir’s name to procure and illegally sell the telecommunications data.
A similar modus operandi was uncovered at the Demra Police Station, where official police email channels were exploited to request CDRs for four mobile numbers using a fictitious case reference. Investigations confirmed that no case was registered on that date and that the named investigating officer, Sub-Inspector (SI) Shah Alam, had never requisitioned the records. Constables Saimum Hossain and Masum Mia allegedly coordinated the unauthorized requests.
Broader Network and Security Vulnerabilities Exposed
Detectives are currently expanding their investigation to identify additional accomplices involved in the racket. Investigative sources stated that active operations are underway to dismantle the entire syndicate and bring all responsible individuals to justice.
This case follows a related crackdown on September 13, when Special Response Battalion (SRB)-2 arrested five individuals—Abdus Salam Sarkar, Subrata Chandra Paul, Ismail Hossain Sohag, SM Nafi, and Md. Mehedi Hasan—in connection with personal data trafficking. Five separate cases were filed against them.
According to SRB findings, the network advertised illegally obtained personal data online, charging clients fees to access CDRs, SIM ownership details, radiolocation tracks, IMEI searches, and mobile financial service (MFS) registration and transaction histories. The primary suspect, Abdus Salam Sarkar—who worked as a temporary employee at the Bangladesh Election Commission between 2018 and 2022—operated an encrypted platform titled
e-sheba24.top to execute data transactions.Data Protection at Stake
Bangladesh currently has over 190 million active mobile subscribers across four telecom operators. Under statutory obligations, service providers maintain subscriber call and text records, which compose CDR datasets. Up to 12 state agencies, including law enforcement and intelligence organizations, hold authorized access to these repositories for official investigations.
However, encrypted communications sent via platforms such as WhatsApp, Signal, and Telegram remain outside the scope of standard CDR monitoring.

