Advertisement

An analysis of data breach epidemic in Bangladesh

An analysis of data breach epidemic in Bangladesh
Representational image: Collected
Advertisement
Advertisement

Two news stories have surfaced in the media that NID information with biometric data is being sold on the internet black market, and call histories along with location information of almost any person are available. These highly sensitive data, used by law enforcement agencies, leaked into the wrong hands can lead to more precise, targeted, and sophisticated criminal activities. 

In 2024, the Confidentiality of the National Telecommunications Monitoring Cell (NTMC) – the national-level intelligence agency of Bangladesh – was breached.

Two high-clearance officials used their NTMC credentials to collect personal data of citizens, such as NID details and phone call detail records (CDR), and later sold the data online. The then NTMC DG Ziaul Ahsan said that the Home Ministry asked the RAB and Police to take steps against them. 

The recent news that CDRs of almost any person are being sold on Telegram and Facebook from Tk500 to Tk1,050 may also raise an unverified yet contextual question of whether this access traces back to insiders like the NTMC case above. 

In January 2026, two EC staff were found siphoning 365,608 NID records in a single month to sell on social media. This indicates that access to sensitive national databases carries no meaningful audit trail, no behavioural monitoring, and no alert system for unusual events like bulk downloads. 

As of the date, around 174 entities like banks, ports, and health services are connected to the central NID database via APIs, assuming a secure one-to-one data pipeline, to ensure different types of verification. Instead of returning a secure yes/no validation, the API transfers the full raw profile of the citizen, and the partner organisations store the transferred data on their own local servers indefinitely without audit or deletion schedules. This is called a shadow copy.  

Advertisement
Advertisement

Earlier in 2025, EC confirmed that five organisations with legitimate API access to the NID system, including the DGHS, a major bank, and the Chittagong Port Authority, had leaked data to third parties.

Dismislab, in an investigation, found an unverified claim from a seller that a group is collecting NID data ‘bypassing government servers through an API’ and selling each at Tk2 to Tk3. If it is verified, there is a need for an emergency investigation into whether any third party can collect confidential data directly from government-held systems without authorisation. 

A January 2026 breach leaked personal details of 14,000 journalists, where manipulating the web address path allowed normal users to increase their privileges to admin and access the personal data of other journalists.

This is the textbook example of Broken Function Level Authorisation. These types of flaws can easily be eliminated in a well-structured software development practice. In June 2026, a group of researchers tested a government portal’s password-recovery feature. At one point, the application crashed. It was in debug mode, used during development to find reasons behind any application crash. 

Related News

As a result, it exposed plain-text administrative passwords to the master database, the cryptographic keys used to validate all active user sessions, and the login credentials for the government’s official email system. This is also a basic security practice: debug mode must be disabled before deploying any application that goes live.  

In Gopalganj, fraudsters posing as authorised telecom agents lure rural citizens with cheap SIM cards. They collected NID numbers and biometric data from victims and used them to register secondary SIMs or Mobile Financial Service (MFS) accounts for committing crimes. This raises the question of whether these agents and shops, which handle sensitive citizen data, are monitored by the authorities. 

Social engineers hosted six look-alike domains using ‘.news’ extensions instead of ‘.gov.bd’ masquerading as the official myGov e-Apostille service. Citizens and intermediaries were tricked into uploading authentic passports, NIDs, and certificates to these fake sites, resulting in 1,100 fake e-Apostille certificates.

They operated these sites long enough to deceive these people. This points to a lack of regular domain monitoring by the authorities responsible for the official services. The incidents have a common pattern. None were disclosed by the institutions concerned before journalists or researchers found them.

Bangladesh’s Personal Data Protection Act (PDPA) 2026 is meant to protect people’s data rights. However, the act has some loopholes that result in such data breaches being underreported, in comparison with the EU’s General Data Protection Regulation (GDPR). PDPA Section 20(1) requires a data fiduciary to notify the Authority when a breach risks ‘significant damage’ to the data subject. PDPA does not clarify the term significant that can be exploited to silence a data breach. GDPR gives controllers 72 hours to notify regulators. Section 20(1) sets no such deadline. 

GDPR suggests sending notification to affected individuals when the risk is high. Section 20(1) only requires notifying the Authority, not the citizen whose data is exposed. This is a likely reason such breaches are mostly known via activists, independent security researchers, or journalists, without official disclosures keeping citizens in the dark. NTMC and the EC should implement mandatory audit logging and alert systems on any bulk download or unusual user activities. They should monitor and conduct regular audits on staff access logs.

For the API (Application Programming Interface) layer, the same accountability applies. EC should enforce strict security compliance requirements for their 174 API consumers. This includes regular activity reporting and resource-consumption monitoring. Non-compliant parties should face a graduated response. This may start with warnings and remediation deadlines, imposing fines, and reserving service suspension as a last resort. Abrupt cutoffs for critical services like health verification or banking may cause public harm. APIs should transfer minimum necessary data, enforce deletion schedules, and undergo regular independent audits. 

Technical product owners at government-facing engineering firms must ensure minimum security testing like OWASP (Open Worldwide Application Security Project) guidelines before any project goes live. Quality assurance personnel should be trained to at least an intermediate level of hands-on security testing. Automated checks can be implemented to detect misconfigurations, such as debug mode left on, before every deployment. Independent application and network penetration testing should be conducted regularly.

BTRC should bring telecom agents and stationery shops under proper monitoring and a formal licensing procedure that holds these entities accountable for data breach incidents. A public, verified registry of domains authorised to operate government-linked services, regular monitoring of look-alike domains and government DNS records would minimise incidents like fake e-Apostille sites. 

The government should also run public awareness campaigns encouraging people to verify any agent, shop, or website before handing over any confidential data.

PDPA 2026 should include a specific notification timeline for informing both the Authority and affected persons about a breach. The Act should include an explicit provision for notifying affected citizens directly, and a clear legal definition of ‘damage.’

These measures require no new technology or foreign expertise. The country’s own security professionals with hands-on expertise already know the fixes. 

The views expressed in this article are solely those of the author

The writer is a Sub Editor, Daily TIMES of Bangladesh

Follow TIMES on Google News

Get trusted updates and editor-picked stories in your feed.

Follow
Related News