A university student from Dhaka’s Maghbazar area left her father in utter disbelief after receiving an official tax demand from the National Board of Revenue (NBR) for Tk25 lakh. The letter named her as the director of a major corporate group.
Her father eventually resolved the matter after an arduous ordeal with tax officials, but the truth proved chilling. “My daughter’s National Identity Card number, phone number, name, and address were all hijacked to register a dummy company,” he told TIMES. “Loans were even drawn from banks in her name.”
His daughter is far from alone. Between January 2023 and May 2026, at least 68 major data breach incidents occurred across Bangladesh, 36 involving public sector bodies and 32 hitting private institutions, according to a report titled “Data Breaches in Bangladesh” by the Tech Global Institute.
The compromised data spans National Identity numbers, biometric details, and passport records. High-profile victims include a government minister whose entire personal dossier was peddled online.
Using stolen credentials, fraudsters have siphoned off hundreds of crores of taka from financial institutions. In September, the Special Response Battalion (SRB), formerly RAB, arrested five individuals including Abdus Salam Sarkar, owner of ‘E-Service Twenty Four Dot Top’, an encrypted portal selling live government data, including real-time location tracking, call records, and SIM registrations.
Law enforcement confirmed the ring breached state servers, though officials declined to identify the insiders who facilitated the access.
Bangladesh’s legal response to cybercrime began with the Information and Communication Technology Act 2006, which largely focused on online speech rather than privacy.
Following the 2016 Bangladesh Bank cyber heist, digital risks gained policy traction, culminating in the Personal Data Protection Act 2026. This landmark statute finally establishes a legal framework for data privacy.
However, legal experts argue that legislation alone is insufficient. Over the past few years, data leaks have routinely been exposed by cybercriminals, threat researchers, or journalists, while affected institutions systematically conceal breaches.
The structural breakdown is further underscored by law enforcement statistics. Between January 2020 and August 2025, the Cyber Police Centre recorded roughly 1,74,000 cybercrime complaints, yet only 40 yielded formal court cases.
The vast majority of grievances linger unresolved due to forensic constraints, evidentiary gaps, and institutional inertia.
Speaking to TIMES, cyber security expert Tanvir Hassan Zoha, also a prosecutor and special investigator at the International Crimes Tribunal, warned that formal regulations mean little without structural audits.
“Most organisations still do not know what data they hold about citizens, where it is stored, or who has access to it,” Zoha noted. “Without creating this basic visibility, a paper-based data protection plan will never keep citizens safe.”
Govt database also targeted
Even state security infrastructure has failed to escape the onslaught.
In 2024, cybercriminals reportedly compromised the credentials of over 1,00,000 police officers, alongside nearly 7,00,000 login records and access to the Crime Data Management System, followed by the theft of 13 gigabytes of internal police files.
Law enforcement offered no official response.
This followed a catastrophic July 2023 breach, where TechCrunch revealed that sensitive data belonging to nearly 5 crore citizens, including National Identity Card (NID) numbers and biometric details, lay exposed on a public Birth and Death Registration server, indexed by Google and distributed via Telegram.
That same year, Biman Bangladesh Airlines lost roughly 100 gigabytes of data, exposing passenger and employee passports.
The crisis has only worsened.
The Election Commission’s NID database suffered two reported compromises in 2025, exploiting partner organisation access and internal vulnerabilities.
By early 2026, allegations surfaced that 3,65,608 citizen records were extracted from the NID system and sold online, with over 1,00,000 records harvested in a single week, underscoring a institutional pattern of silence and systemic failure to safeguard the nation’s most sensitive repositories.
Organisations deny breaches
Despite mounting evidence, not a single major organisation in Bangladesh has ever publicly admitted to a data breach. Instead, corporate leaders routinely issue blanket denials when confronted with massive leaks.
When the cybercriminal syndicate ‘Madarax’ claimed to have sold the personal records of six million job seekers from Bdjobs on the dark web, its Chief Executive Officer AKM Fahim Mashrur dismissed the allegation out of hand.
Similarly, after cybersecurity firm SoC Radar revealed that more than 4.2 million customer records had been exfiltrated from online retailer Ghorer Bazar, the company insisted its user data remained entirely secure.
However, state officials paint a starkly different picture.
The Bangladesh e-Government Computer Incident Response Team (BGD e-Gov CIRT) confirmed it had formally alerted both entities to active cyberattacks. While Bdjobs subsequently sought technical assistance, Ghorer Bazar ignored the warning altogether.
According to CIRT officials, this reflexive denial is standard practice.
Fearing reputational damage and commercial fallout, institutions consistently opt to conceal breaches, sacrificing citizen privacy to protect their own public image.
Administrative chaos hamstrings cyber defence
A labyrinth of overlapping state agencies has left Bangladesh’s cybersecurity apparatus fatally fragmented.
While the BGD e-Gov CIRT monitors technical threats, the National Cyber Security Agency (NCSA) oversees national policy, the Cyber Police Centre investigates crimes, and the telecommunications regulator handles online content.
When a breach strikes, this bureaucratic maze collapses into confusion. Crucial questions remain unanswered: who coordinates the emergency response, who enforces remediation, who secures forensic evidence, and who leads the criminal probe?
Without a unified command centre, responsibility is routinely shuffled between bodies. When approached for comment on these institutional blind spots, NCSA Director of Operations Mohammad Hossain Bin Amin requested written queries, and offered only silence afterwards.
Cybersecurity experts warn that without a single lead authority, investigative data becomes hopelessly scattered. Compounding the crisis, NCSA officials admit that policy gaps persist regarding third-party vendors and external data processors, leaving citizens’ most sensitive information vulnerable in the administrative void.
Gaps in the law leave victims in the dark
The Personal Data Protection Act 2026 contains critical loopholes that threaten to undermine its purpose.
Under Section 20, data custodians are required to report breaches only if there is a threat of “significant harm”, yet the statute fails to define the threshold.
Crucially, while the law compels entities to inform regulators, it contains no clear obligation to notify affected individuals. Consequently, citizens whose National Identity Card details, addresses, or banking credentials are leaked remain completely oblivious to the threat.
This absence of mandatory victim notification deprives individuals of the chance to safeguard their accounts or counter identity theft before damage occurs.
Legal expert Tanvir Hassan Zoha warned, “If the obligation to directly inform citizens is not clearly defined, they may suffer irreparable harm before they even discover their personal information has been compromised.”






