REPORT Data breaches in Bangladesh · 2023–2026

TECH GLOBAL INSTITUTE

BREACHED AND UNANSWERED

A Cartography of Bangladesh's Data Breach Epidemic

Apon Das · Mir Rownak · Kalim Ahmed · Shahnewaj Patwari · Fowzia Afroz · Shahzeb Mahmood

EXECUTIVE SUMMARY

The breaches were found by almost everyone except the institutions that suffered them

Between January 2023 and May 2026, at least 68 data breach incidents affecting both government institutions and the private sector appear to have occurred in Bangladesh. Drawing from cybersecurity advisories, dark-web monitoring services, threat-intelligence feeds, and mainstream newspapers, our findings revealed that of these data breaches, 36 involved government organisations and 32 involved private ones. The data exposed across these incidents includes, but is not limited to, national identity numbers, biometric records, passport details, and other personally identifiable information.

A second finding runs throughout almost every incident in the dataset: the failure of institutions to recognise warning signs of a data breach — institutional blindness. Almost all documented cases involved breaches identified by external security researchers, news outlets, or dark-web monitoring services rather than by the affected organisations themselves; the two rare exceptions were the Bangladesh Election Commission's detection of leaks within its own verification ecosystem and one police investigation into an alleged breach. Where a response can be traced at all, it is far more often silence or denial than an acknowledgment, and a published post-mortem or forensic analysis is rare to the point of near-absence. These organisations also do not run bug bounty programs that reward the good actors who tend to surface these vulnerabilities and report them via the institutions' official channels.

"Most organisations in the dataset did not have systemic organisational controls to know they had been breached."

On the absence of round-the-clock security operations and proactive threat hunting

Data breaches in Bangladesh have escalated into a critical national security crisis, yet the systemic response from the government and key stakeholders remains largely inadequate. The consequences extend far beyond individual privacy violations, affecting state security, public trust in digital services, and the integrity of critical institutions. Despite the growing frequency and severity of breaches, Bangladesh still lacks robust accountability mechanisms, mandatory breach notification requirements, and effective institutional responses to protect citizens' data and hold organisations accountable. This report addresses these systemic vulnerabilities by highlighting the immediate risks, identifying critical gaps in the existing policy and legal frameworks, and proposing actionable pathways toward institutional accountability.

BACKGROUND

From a laminated card to the key that opens every door

Two decades ago, the average Bangladeshi citizen's life revolved around papers: paying utility bills, accessing government subsidies and welfare, transferring money, or checking a bank balance meant navigating bureaucratic burdens in person. Then the introduction of the national identity (NID) and, in subsequent years, the initiation of Digital Bangladesh and later Smart Bangladesh, significantly changed how day-to-day civic engagements were carried out.

Stage 1
PAPER

Paper NID

A laminated card that did one thing: establish identity.

Stage 2
||||||||

Machine-readable biometric card

Supported by the World Bank via its IDEA project.

Stage 3

Smart NID

An embedded microchip reportedly storing impressions of all ten fingers, iris scans, 32 unique citizen data types, and 25 security features.

The scale of digitisation the NID now anchors

81M

Smart NID cards prepared by late 2024, against ~122M registered voters

83M

People online by end of 2025 — about half the country

186M

Mobile connections supporting that digital footprint

200M+

Registered mobile-financial-service accounts, of which 89.38M are active

While this digitalisation offers greater convenience to the lives of millions, it has created a fundamental shift in what an identity document does. The paper NID was simply about establishing identity; the smart NID is about access that permeates every walk of life. Each interaction - a tap to check a balance or pay a bill - is a request passed through an API, a small act of permission that lets a system reach into data tied to you: your name, your parents' names, your date of birth, your fingerprints, and over two dozen other data points in total.

This intermediated access regime isn't new - it existed even in the paper era, just with a human layer wrapped around it. When a citizen walked into a bank to inquire about a deposit, the clerk did not hold that data personally; instead, the clerk queried a system that already had programmatic, API-level access to it, and the query was simply mediated by a human interface. Consequently, what digitisation changed was the removal of that human layer, so the request now runs directly between citizen and system rather than through an intermediary. Over a decade, that accumulation gave Bangladesh an enormous, concentrated store of its citizens' data - and each new service built atop it has extended a further layer of access to government institutions, private bodies, and others. Meanwhile, the safeguards that should accompany such concentration - robust security practice, data-protection law, and institutional oversight — have consistently been, and continue to be, deferred.

DEFINITIONS

What constitutes a data breach?

A data breach, in plain terms, is when information about you ends up somewhere it was not meant to go. The “how” aspect of it varies. A hacker group may break into a system and take the data; or an organisation simply leaves a digital door open, allowing the data to remain exposed or spill out by accident.

The method and motive differ. What stays constant is the outcome: people's information ends up outside the bounds it was meant to stay within, often in hands of people who were never authorised to access it.

Personal Data Protection Act, 2026

"A personal data breach means a breach of security of personal data resulting in unauthorised access to or unlawful transfer, disclosure, alteration, or loss of or intrusion into any personal data processed under this statute, or in the absence of the necessary equipment for proper processing and storage."

Similar definitions exist in regulations elsewhere around the world, including the so-called gold standard for global data protection, the EU General Data Protection Regulation.

In most cases the information at stake is Personally Identifiable Information (PII): any fact, or combination of facts, that can be traced back to a specific person — a name, a phone number, a national identity number, an address, or biometric data such as fingerprints and iris scans. The list is illustrative, not exhaustive.

Why a PII leak is consequential: not all of it can be taken back

Revocable

A leaked password or payment PIN is recoverable. You reset it and move on.

Irrevocable

Your biometrics: the patterns in your fingertips, the structure of your iris - cannot be reset. Once exposed, they cannot be revoked or reconfigured.

As this collection of data began mapping onto nearly every domain of Bangladeshi life, a trade-off was set in motion the moment the paper NID became the stepping stone toward Digital Bangladesh.
Once a single identity links every essential interaction, the convenience it delivers also carries visibility: the state can see, in one place, what each citizen does. The same concentration of data also creates opportunities for private actors, whether through commercial profiling, data exploitation, or unauthorised access, to gain unprecedented insight into individuals' lives. A concentration of data is therefore not only a criminal's prize but also an instrument of surveillance and control.
In cybersecurity terms, those who exploit such data are called threat actors. Although the term typically refers to external adversaries, the same concentrated data are also, in most cases, lawfully possessed by the state. An enhanced surveillance capability does not need bad intentions to cause harm because once a single identifier maps individual identity to activity, it lowers the cost of finding a person, monitoring dissent, and applying pressure at scale.

THE COUNT AND SPLIT

The numbers best state the material reality of the problem

Tech Global Institute compiled a dossier of 68 documented breach incidents affecting Bangladeshi organisations between 2023 and 2026, drawn from four categories of sources: localised threat intelligence from Bangladesh Cyber Security Intelligence (BCSI); international dark-web and ransomware monitors (Ransomware.live, Ransomlook.io, RedPacket Security); threat-alert aggregators (Daily Dark Web on X); and national dailies including The Daily Star, Prothom Alo, and The Business Standard. For each incident, TGI logged the data exposed, the vector (where known), who discovered the breach, whether the organisation acknowledged it, whether any post-mortem followed, and the verification status of the claim.
Details of the methodology are available in the Appendix.

How incidents are attributed

Attribution follows the data controller: each incident is logged against the institution whose data was exposed, even where the leakage occurred through a partner organisation's authorised access or an insider rather than through a compromise of the institution's own systems. Several incidents linked to the Bangladesh Election Commission are of precisely this kind — citizens' NID data leaking through verification channels operated by private and public entities — and are counted against the country's electoral agency as custodian of the national identity database. The government–private distinction should be read with that convention in mind: it describes where the exposed data lived, not necessarily where the security failure occurred.

Documented incidents by year and sector

Government Private
6
1
9
18
8
6
13
7
2023
7 total
2024
27 total
2025
14 total
2026
20 total · Jan–May

With the exception of 2024, breaches were more frequent in the public sector than in the private sector in every year of the covered period.

The headline finding

The targets moved from the state's core to the shop floor.

36 government vs 32 private

Neither sector has been spared: a near-even split over the 41-month window means the exposure is systemic, not sectoral.

Reading the numbers

Volume figures originating from criminal sources are the claims of threat actors themselves, and may be exaggerated for extortion purposes. Each incident is therefore tiered by evidentiary strength — see the verification key in the Appendix.

A note on scope

However, these incidents represent only those that could be identified and corroborated through TGI's source matrix and methodology. Additional breaches may have escaped detection, remained confined to private disclosures, or gone entirely unreported. As such, this dataset should be understood as a documented baseline rather than an exhaustive census of breach activity, offering a conservative view of the broader cyber risk landscape rather than a complete accounting of it.

WHO WAS HIT

Widespread exposure across public and private domains

A closer look at the affected entities shows that the overwhelming majority are formally structured organisations — government ministries, regulatory bodies, financial institutions, registered private enterprises, and other entities that maintain large-scale databases containing extensive personal information on citizens — rather than informal or unregistered entities.

While indicative, this pattern should not be interpreted as suggesting that organisational scale alone determines exposure. Rather, it reflects one of several factors that shape cybersecurity risk in an increasingly digitalised economy, where the growing volume and value of data held by public and private institutions, together with extensive digital infrastructure, interconnected systems, and large repositories of PII, make certain organisations particularly attractive targets. At times, the incentive lies not merely in the volume of data, but in its economic or strategic value. For example, institutions connected to overseas employment and inward remittances may hold information on individuals with predictable income flows, making such datasets especially valuable to cybercriminals.

Approximate distribution of data breaches by organisation type

Government services and utility providers20
Private companies and business groups16
Bangladesh Election Commission–linked5
Telecommunication and internet service providers5
Armed forces3
Private banks and mobile financial service providers3
Four categories with 2 incidents each8

Law enforcement & intelligence agencies · Government ministries · Government banks · Retailers

Eight categories with 1 incident each8

Government airline · National Parliament of Bangladesh · Bangla Academy · Government educational institution · Private airline · Private educational institution · Media · E-commerce

Most recurrent in the dataset

The Bangladesh Election Commission — steward of the national identity database

The electoral agency is linked to at least five incidents: the exposure of NID-linked voter data on Telegram in October 2023; the leakage of citizens' NID data through five partner organisations' verification access in February 2025 — DGHS, Upay, the Chattogram Port Authority, the Department of Women Affairs, and iBAS++, which drew show-cause notices — and two others (Ansar-VDP and BRAC Bank, suspended) in May 2025; the insider syndicate uncovered by the Criminal Investigation Department (CID) in January 2026; and the exposure of roughly 14,000 journalists' accreditation records through a flaw in an agency-run portal days later.

Two features of this record require elaboration. First, in none of these cases has an external intrusion into the agency's central NID database been publicly established; the agency has maintained that its core systems were not hacked, and nothing in our dataset contradicts that. Second, and precisely because of that, the recurring failure mode is the ecosystem built around the database — authorised third-party verification channels, several of them operated by private institutions, and insiders holding valid credentials. The remedy therefore turns less on firewalls and more on access governance, contractual controls, continuous monitoring, and sanctions.

Of particular concern

Stolen Credentials, Leaked Lives: The NTMC Breach

The National Telecommunication Monitoring Centre (NTMC) is known to intercept phone calls, emails, and social media communications, to collect and retain communication data, to filter and block online content, and to support broader national security and public order objectives through communication intelligence. It reportedly operates a platform through which nearly 500 officials from 42 public organisations are authorised to access citizens' data for verification and investigative purposes. According to reports, the NTMC system was exploited using the credentials of two law enforcement officers to collect and sell — via encrypted messaging services — confidential information, including NID information and mobile call data records, for financial gain. An incident of unauthorised access and data exfiltration and breach involving an agency of this nature is categorically different from a breach at a retailer or news portal as the data it handles is not merely personal or financial, but intercepted communications and surveillance records that, if exposed or misused, could compromise the privacy and safety of individuals being monitored, reveal intelligence methods, or be exploited by malicious actors for blackmail, targeted harassment, or further unauthorised surveillance.

A ministry holding millions of migrant-worker records

The alleged breach of the database of the Ministry of Expatriates' Welfare and Overseas Employment reportedly compromised passport records, NID information, electronic tax identification number (eTIN) details, and financial and banking documents along with transaction records — identity, tax, and financial information in a single dataset. That combination could be exploited for multiple malicious purposes, including voter manipulation, blackmail, identity-based scams, and financial fraud targeting one of the country's most economically significant demographics.

Custodians of national security and elections

The appearance of armed forces agencies, ministries, and the Bangladesh Election Commission among breached entities raises the stakes considerably. Unlike commercial breaches, where the primary harm is financial or reputational, breaches in this category carry the potential to escalate into national-security incidents or to directly infringe on citizens' fundamental rights.

A TIMELINE OF DATA BREACHES, CIRCA 2023–2026

A clear escalation — in frequency and in severity

The earliest incidents were largely ransomware campaigns and isolated database exposures; over time, the threat landscape broadened into large-scale leaks of citizen data and attacks on critical infrastructure, government agencies, financial institutions, telecom providers, and major private firms. As the incidents accumulate, a second pattern is observed: institutional negligence and lack of preparation. Below are ten major incidents — the complete 68-incident table is in the Appendix.

{{ m.d }} {{ m.sec }} {{ m.vLabel }}

{{ m.org }}

Exposed{{ m.exp }}

Discovered through{{ m.dis }}

A closer dissection, year by year

{{ p }}

Continue reading
WHAT THE TIMELINE SHOWS

What follows the breach is the most telling of all: relative silence

More often than not, the affected institutions have failed to find the breach, not acknowledging it once others did, and never accounting for how it happened. What recurs across these years is a trend of concealment: breaches brushed over, denied, or left to fade, while the same failures — insecure databases, loose access controls, leaky third-party arrangements, compromised credentials — go unaddressed or are secretly patched because they are never openly named.

Aggregated totals also flatten the picture. A count of incidents tells you how often breaches happened, but it cannot tell you that the same target was hit deliberately, more than once. Several institutions in the dataset were targeted, or claimed as targets, on separate occasions: the Bangladesh Election Commission's NID ecosystem (five incidents — through partner channels, insiders, and a flawed portal rather than any established intrusion into the central database), the country's road-transport agencies (one verified breach followed by two unverified sale listings), the armed forces (three separate leak-site claims, none independently verified and one made by an actor known to recycle false claims), and, most tellingly for what follows, the country's migrant-worker data systems.

The migrant database

The population exposed is among the most vulnerable to follow-on fraud: migrant workers and their families, who already navigate multiple middle players and associates, are exactly the people a scammer armed with a leaked passport number and other PII can most easily deceive. It is equally concerning in a democratic context, as malicious actors can exploit the personal credentials of citizens living abroad to engineer proxy voting, manipulate postal ballots, or execute targeted voter suppression. Given the large number of overseas Bangladeshis, such breaches pose significant risks to the integrity and credibility of national elections.

The target worth returning to

3×hits on migrant-worker databases in roughly six weeks (Apr–May 2026) — first, second, third

Databases linked to the Ministry of Expatriates' Welfare & Overseas Employment, its overseas-worker platforms, and the manpower and training bureau — together involving claims of well over a million migrant-worker records, passport details included.

$30B+

Remittances in FY 2024–25 — a national record

6.57%

Of GDP — financing close to half the import bill

The flow is still accelerating: the latest data show inflows reached US$3.42 billion in May 2026, up more than 15% year-on-year (US$2.96 billion in May 2025).

More importantly, the attacker(s) are seemingly aware that this is not a one-time flow but a recurring one. Remittances proved resilient through the COVID-19 pandemic and rebounded within months of the political upheaval of 2024, because the underlying behaviour of a worker abroad sending money to family at home repeats month after month and year after year. A breached passport number or overseas contact detail is valuable every time the next remittance is due, as it can be leveraged repeatedly for phishing, identity fraud, account takeover attempts, and other scams timed to intercept or exploit recurring financial transactions. Evidently, remittances are predictable and repeated, and that rhythm turns the workers behind them into predictable, repeated marks.

The bigger takeaway: the data being exposed has grown more permanent and more central to civic life over time, even as the institutions holding it have shown, through repeated breaches, that they are not learning from each hit.

LEGAL ANALYSIS

Unanswered on all fronts: the systemic accountability deficit across public and private sectors

Breaches split almost evenly and so does the accountability gap: the same lack of transparency, mandatory breach notification, and published post-mortems leaves citizens exposed on the state and corporate sides alike.

36 Government
32 Private

A review of available sources on the 68 incidents identifies limited instances in which legal actions were meaningfully pursued against a breached entity or a responsible party. This absence of enforcement is significant not simply because Bangladesh lacks an adequate statutory framework governing data protection, but because the frameworks that exist have not yet produced an operative accountability mechanism capable of translating statutory rights and obligations into enforceable outcomes.

Sector-specific instruments

The National Identity Registration Act, 2023 treats NID information as confidential and criminalises unauthorised access to and disclosure of such information, while simultaneously preserving formal pathways for third-party access, although those conditions remain vague and insufficiently defined in practice. While there have been reports of investigations and arrests in connection with alleged unlawful access to and sale of NID information from within the Bangladesh Election Commission, the cases involved operational and support personnel, not senior officers. Moreover, it remains unclear whether the accused were ultimately prosecuted under the statute, or whether the incidents prompted broader institution-wide reforms to strengthen governance and oversight. Similarly, although the Bangladesh Election Commission has, on several occasions suspended or terminated third-party organisations following alleged data irregularities, there is little publicly available information on whether the individuals responsible were subject to legal or disciplinary sanctions beyond the suspension or termination of their organisations’ access.

Within the banking sector, the Bank Companies Act, 1991 restricts the cross-border transfer of banking information while mandating confidentiality in information management. Similarly, the Bangladesh Telecommunication Act, 2001 criminalises the unauthorised disclosure, by operators and associated individuals, of information transmitted over telecommunication networks, while prohibiting regulatory officials from unlawfully disclosing information obtained in the course of their duties. Yet both are structured around isolated and narrowly framed confidentiality provisions rather than a coherent regulatory scheme: no mandatory breach notification, no clear post-breach institutional responsibilities, no meaningful avenues of redress — and no publicly reported, precedent-setting judicial or administrative decisions establishing institutional accountability for large-scale breaches.

Under the now-repealed Digital Security Act, 2018, it was a criminal offence to collect, sell, possess, supply, or use another person's PII without lawful authority. Yet during the law's five-year operation between 2018 and 2023, despite more than 7,000 cases reportedly filed under it, there appear to have been no publicly reported prosecutions invoking this provision in relation to data breach incidents — an absence that persists across its three successor enactments, including the currently operative Cyber Protection Act, 2026, over nearly eight years of Bangladesh's cybercrime legislation.

The 2026 suite

The Personal Data Protection Act, 2026 emerged only recently and, for the first time, defined and introduced a statutory data breach notification obligation. However, the obligation is narrowly framed: notification is required only where a breach is likely to cause “significant damage” to the data subject, while the form, content, and timeframe for notification are deferred to future regulations, and the provision mandates notification to the Personal Data Protection Authority but does not expressly require timely notification to affected individuals. And despite recognising data-subject rights and requiring appropriate technical and organisational safeguards, the statute's breach framework falls short of ensuring meaningful accountability in several respects that remain central to any serious legal diagnosis.

Four interlocking deficiencies

Viewed collectively, the laws assessed leave an accountability vacuum. Statutory obligations exist, and remedial provisions are drafted, but who bears responsibility for a breach, through which forum liability is to be established, and under what timeline enforcement is to occur remain legally unsettled. Until the transitional provisions are activated, the interlocking relationship between administrative, civil, and criminal remedies is clarified, the interpretation of the exemptions is settled, and the independence of the enforcing authority from public-sector fiduciaries is institutionally secured, Bangladesh's data protection regime is likely to remain — as the pattern across the 68 documented incidents, the overwhelming majority of them never publicly investigated, remediated, or even acknowledged, suggests — a framework of formal rights without a corresponding structure of practical enforcement.

RECOMMENDATIONS

Five actionable pathways toward institutional accountability

{{ p }}

LOOKING AHEAD

An uneven future requires stronger fundamentals

JUNE 2026 · A FIRST-PERSON CASE STUDY

While compiling this report, one crashed password-recovery page handed us the keys to a government system

While compiling this report, TGI's research team conducted a routine assessment of a public-facing government portal. During a standard test of the portal's password recovery feature, the backend server crashed. Because the application had been left running in debug mode, the error response exposed the portal's entire internal configuration file directly in the browser — a comprehensive snapshot of the internal architecture: plain-text administrative passwords to the master database, the cryptographic keys used to validate all active user sessions, and the login credentials for the government's official email system.

Anyone in possession of the exposed credentials could potentially authenticate as a legitimate user from within the trusted environment, leaving the system unable to distinguish between an authorised user and an attacker using the compromised credentials — which is why perimeter blocking alone offers no protection here.

The findings were reported to the Bangladesh Computer Emergency Response Team (BGD e-GOV CIRT) the same day. Their official response did not dispute anything we had documented; in fact, it acknowledged identifying further gaps in the system.

Our diagnosis

Bangladesh is undergoing an ambitious digital transformation, and the political and institutional momentum behind this expansion is evident. Yet the foundational disciplines that underpin secure digital infrastructure — routine security audits, configuration management, identity governance, and continuous assurance — have not matured at a commensurate pace. Our assessment is that the country's most immediate cybersecurity risks receive neither the policy priority nor the public attention they warrant. Instead, the discourse is often drawn toward more politically salient and technologically fashionable issues, such as artificial intelligence, online content regulation, and foreign influence operations, while the less visible but far more consequential investments required to reduce systemic risk remain persistently neglected.

The exposures documented in this report are attributable not principally to exceptionally capable adversaries, but to an institutional culture of complacency reflected in preventable failures of governance, security engineering, and operational discipline. In such an environment, sophisticated adversaries need not overcome robust defences; they need only exploit weaknesses that should never have remained exposed.

METHODOLOGY & FULL DATASET

How this dossier was built

This report utilises a descriptive, exploratory mixed-methods design to investigate the landscape of data breaches in Bangladesh between January 2023 and May 2026, combining quantitative content analysis with qualitative thematic analysis to map the frequency, distribution, and systemic patterns of incidents across both public and private sectors. The primary dataset was compiled from 68 documented incidents, aggregated from four categories of sources: localised threat intelligence from Bangladesh Cyber Security Intelligence (BCSI); international dark-web monitoring (Ransomware.live, Ransomlook.io, RedPacket Security); threat-alert aggregators, principally Daily Dark Web; and mainstream media reporting from national dailies including The Daily Star, Prothom Alo, and The Business Standard.

For each recorded incident, we systematically logged eight data points: date; organisation and sector; type of data exposed (as claimed); attack vector (where known); discovery mechanism; whether the organisation acknowledged the incident; whether any post-mortem was published; and the verification status of the claim.

To complement the quantitative findings, we conducted a qualitative policy and legal analysis: a systematic review of Bangladesh's sectoral and general data and identity laws, including the National Identity Registration Act, 2023, and those governing cybersecurity, banking, and telecommunication, together with the Personal Data Protection Act, 2026 and the National Data Management Act, 2026. By tracing the historical progression, we aimed to evaluate the "sequencing gap" between the rapid deployment of digital public infrastructure and the delayed development of rights-protective privacy legislation. This analysis specifically examined, at a high level, how vague provisions, wide executive discretion, and fragmented enforcement mechanisms, rather than a total absence of law, contributed to the systemic vulnerabilities and institutional silence observed in our incident dataset.

Limitations. First, the dataset reflects only reported and discoverable breaches; the true frequency of incidents is almost certainly higher. Second, because we rely on a mixture of official advisories, news reports, and third-party threat-intelligence claims, the volume figures cited are often based on the claims of the threat actors themselves, which may be exaggerated for extortion purposes. We have categorised these findings with confidence tiers distinguishing between verified incidents, reported but unconfirmed events, and unverified dark-web claims to ensure transparency regarding the evidentiary strength of each case. Third, incident narratives are summarised for this report, and where specific data samples are discussed, they are treated in aggregate to maintain the privacy of the victims.

Verification key — the 68 incidents by tier

32 verified — confirmed by a national authority (BCSI or CIRT), the breached organisation's own acknowledgment, or substantive mainstream reporting
5 reported, unconfirmed — a credible outlet noted the claim, but it was not officially confirmed and we could not independently verify
31 unverified claims — exist only as leak-site or dark-web-forum listings, not independently confirmed

"Exposed" figures originating from criminal or leak sources are claims, not confirmed counts. Where a field cannot be established from the available evidence it is marked plainly ("Not disclosed", "None published", "No public acknowledgment found").

Showing {{ rowCount }} of 68 incidents

Date Organization Sector Data exposed / claimed Attack vector Discovered through Acknowledged? Post-mortem? Verification
{{ r.d }} {{ r.org }}
{{ r.cat }}
{{ r.secLabel }} {{ r.exp }} {{ r.vec }} {{ r.dis }} {{ r.ack }} {{ r.pm }} {{ r.vLabel }}
{{ r.verText }}
AUTHORS
AD
Researcher
MR
Research Associate
KA
Research Manager
SP
FA
Country Head, Bangladesh
SM
Head of Research
Tech Global Institute

Tech Global Institute is a policy lab with a mission to reduce equity and accountability gaps between technology platforms and the Global Majority.

Contact

8 Brunswick Street
Brampton, ON L6X 4Y6, Canada

info@techglobalinstitute.com

Follow

© 2026 Tech Global Institute · Data Breaches in Bangladesh, 2023–2026