Advertisement

Online black market trades call records, personal data: DismisLab

Online black market trades call records, personal data: DismisLab
Representational image: Collected
Advertisement
Advertisement

Data detailing whom individuals call, when, for how long, and even their physical location is reportedly being sold online, according to an investigation by fact-checking organisation DismisLab.

Sellers claim to provide records spanning three months to a year within hours, charging anywhere from a few hundred to several thousand taka.

The illicit marketplace offers far more than Call Detail Records (CDRs). National Identity (NID) and passport details, SMS logs, real-time mobile locations, Taxpayer Identification Numbers (TINs), and Mobile Financial Service (MFS) account details are also reportedly available.

Advertisements are posted across Facebook and other social media platforms, with transactions coordinated via Telegram and WhatsApp, and payments processed through MFS providers such as bKash, Nagad, Rocket, and Upay.

NID obtained in 17 minutes

During a month-long investigation from 15 June to 15 July using the search term “sign copy”, DismisLab identified 675 Facebook posts, 605 of which advertised personal data for sale.

Sellers stated that these “sign copies” contained sensitive personal details, including NID and voter numbers, dates of birth, parents’ names, educational qualifications, marital status, occupations, addresses, religious affiliations, physical identifiers, signatures, and fingerprints.

Advertisement
Advertisement

Following up on one Facebook advertisement, a DismisLab reporter joined a Telegram group where an account named “Shibat Zubar” offered to retrieve NID records using mobile numbers. With a customer’s consent, the reporter paid Tk500 in advance and received a full NID PDF within 17 minutes.

The data – including the subject’s name, photograph, date of birth, and recently updated mother’s name – was verified as accurate. A second test yielded equally precise results.

Another vendor provided an NID PDF for Tk150 using only a voter number and date of birth, while a “sign copy” obtained via another individual’s mobile number cost Tk250.

Related News

Three months of call logs in 2½ hours

DismisLab subsequently ordered three months of CDR data for a Grameenphone number. Upon paying Tk1,050, the team received the requested file within two and a half hours.

The last 20 contact numbers, call timestamps, and call types in the file were cross-referenced with the subscriber’s actual call history and matched perfectly.

CDRs can reveal a subject’s full communication profile, including contact numbers, duration of calls, call direction (incoming or outgoing), network operators, and the device’s IMEI and SIM card IMSI numbers.

Crucially, tower and network-cell metadata can pinpoint a phone’s location, allowing bad actors to map an individual’s movement patterns over time.

Mobile location traced in 16 minutes

DismisLab identified 10 active websites selling personal data, driven by traffic from Facebook posts and connected WhatsApp and Telegram channels. These portals offered NID, birth registration, TIN, CDR, and location data, among other sensitive records. At least one domain was registered in 2025.

DismisLab traced the owner of one such portal to a mobile phone repair technician in Chandpur. Following a payment, the website returned the latest active timestamp, tower-based location, physical address, and a direct Google Maps link for a Grameenphone number in just 16 minutes.

DismisLab noted that it could not independently verify all vendor claims regarding the original sources of the leaked data.

Over 600 advertisements in a single month

The investigation uncovered more than 600 advertisements listing at least 112 unique mobile contact numbers. A single Grameenphone number was cited in 75 separate posts. Personal data was systematically promoted across 36 active Facebook groups, whilst 10 distinct MFS numbers were embedded across 10 websites to collect payments.

Given that the investigation tracked only a single keyword on one social media platform, DismisLab highlighted that the actual scale of the black market is likely significantly larger.

Many social media vendors operate as intermediaries, purchasing bulk data from primary websites and reselling it at marked-up prices via messaging applications.

The Chandpur-based site owner admitted to purchasing a subscriber’s call log for Tk800 and reselling it for Tk900. He also offered identity documents used to open a bKash account for Tk1,000, and full account details for Tk4,500.

He claimed the data was sourced via an external group using an API to bypass government server security. DismisLab was unable to independently verify this assertion or confirm the identity of the primary data suppliers.

Severe risks and legal framework

IT expert Suman Ahmed Sabir warned that compromised NID records can be exploited to set up fraudulent accounts, commit identity theft, or construct synthetic identities. When combined with financial data, these leaks facilitate fraudulent transactions and can enable bad actors to siphon funds directly from legitimate bank and MFS accounts.

Under Bangladesh’s Personal Data Protection Act, personal information gathered for a specific purpose cannot be shared or disclosed for secondary purposes without explicit consent. The law provides a framework for formal complaints and mandates administrative fines of up to Tk25 lakh for compliance breaches.

Follow TIMES on Google News

Get trusted updates and editor-picked stories in your feed.

Follow
Related News