Claims have surfaced that customer data belonging to Bangladeshi e-commerce platform Ghorer Bazar has been offered for sale on a dark web platform.
According to a report by cybersecurity monitoring firm Socradar, an unidentified entity claims to possess more than 4.2 million records belonging to the company.
Amongst these files, the seller purports to hold personal details of over 600,000 customers. However, whether this information was genuinely extracted from Ghorer Bazar’s servers remains independently unconfirmed.
Conflicting claims, unaddressed technical details
The Socradar report, published on 14 September, detailed claims made on a hidden online forum regarding the 4.2 million records. The alleged leak includes over 600,000 customer profiles, more than 372,000 addresses, over 449,000 purchase orders, and nearly two million product delivery logs.
Moreover, the seller claimed to hold internal management files and customer service conversation logs.
Yet, these remain unverified assertions by the seller, and no independent technical verification has publicly confirmed whether the data is genuine or taken directly from Ghorer Bazar’s servers.
On the other hand, Ghorer Bazar maintains that its customer data is completely secure and that shoppers have no reason to be concerned. When contacted by TIMES of Bangladesh for clarification, Ghorer Bazar reiterated its stance.
In an official statement, the platform noted, “Ghorer Bazar’s customer data is secure. There is no reason for our respected customers to be concerned. You can remain assured and confident. We have already taken necessary measures to identify the source of the information being circulated.”
Meanwhile, the company’s Sales and Customer Experience Executive Mohammad Sakib assured that following complaints from several customers, the company’s IT and investigation teams are examining the matter.
He added that the teams have so far uncovered no evidence, meaning the company is, at this stage, unable to verify the claim.
However, the response left several key technical questions unaddressed, failing to clarify whether any unauthorised server breach occurred, whether samples of the leaked data were analysed, or if an independent technical investigation had been launched.
How leaked data fuels convincing scams
If these allegations prove true, everyday consumers could face serious risks. When details like names, phone numbers, email addresses, residential locations, and purchasing habits fall into the hands of criminals, they can be exploited for targeted fraud.
Imagine a scenario where a scammer possesses your name, mobile number, home address, and precise details of your past orders. They could call claiming that a refund is due on a previous purchase, or that a parcel is currently stuck and requires payment to release.
Because they know your actual shopping history, the trick instantly gains credibility. From there, the fraudster sends a fake link, requesting secret numbers, passwords, or mobile banking credentials.
Many assume that as long as banking passwords or PINs remain safe, a leaked residential address or order list is harmless.
In reality, combining a person’s name, mobile number, home address, and purchase logs allows criminals to construct dangerously convincing scams. Such stolen data can also be used to send fake messages impersonating the organisation to extract further sensitive details from customers.
Lessons from past breaches
Cybersecurity incidents of this nature are not unprecedented, having occurred both globally and within Bangladesh.
Globally, a massive cyber incident involving hotel chains Marriott and Starwood exposed names, addresses, emails, phone numbers, dates of birth, and passport details.
According to the US Federal Trade Commission, over 340 million customers worldwide were affected across multiple breaches involving Marriott and Starwood.
Closer to home, Biman Bangladesh Airlines suffered a major cyberattack on its computer systems in 2023, where attackers demanded $5 million and threatened to leak around 100 gigabytes of data containing passenger passport details, flight records, cargo logs, and employee files.
To guard against potential fraudsters, consumers must exercise heightened vigilance. Under no circumstances should customers share secret PINs, passwords, bank card details, or mobile banking PINs with anyone claiming to represent Ghorer Bazar or delivery firms.
Shoppers should also avoid clicking on unfamiliar links sent under the pretext of order confirmations, product returns, refunds, or delivery fee collections.
Ultimately, determining whether the alleged Ghorer Bazar breach is real or entirely baseless will depend on the findings of a comprehensive technical investigation.




