A data breach, in plain terms, is when information about you ends up somewhere it was not meant to go. The
“how” aspect of it varies. A hacker group may break into a system and take the data; or an organisation
simply leaves a digital door open, allowing the data to remain exposed or spill out by accident.
The method and motive
differ. What stays constant is the outcome: people's information ends up outside the bounds it was meant
to stay within, often in hands of people who were never authorised to access it.
Personal Data Protection Act, 2026
"A personal data breach means a breach of security of personal data resulting in unauthorised access to or unlawful transfer, disclosure, alteration, or loss of or intrusion into any personal data processed under this statute, or in the absence of the necessary equipment for proper processing and storage."
Similar definitions exist in regulations elsewhere around the world, including the so-called gold standard for global data protection, the EU General Data Protection Regulation.
In most cases the information at stake is Personally Identifiable Information (PII): any fact, or combination of facts, that can be traced back to a specific person — a name, a phone number, a national identity number, an address, or biometric data such as fingerprints and iris scans. The list is illustrative, not exhaustive.
Why a PII leak is consequential: not all of it can be taken back
A leaked password or payment PIN is recoverable. You reset it and move on.
Your biometrics: the patterns in your fingertips, the structure of your iris - cannot be reset. Once exposed, they cannot be revoked or reconfigured.
As this collection of data began mapping onto nearly every domain of Bangladeshi life, a trade-off was
set in motion the moment the paper NID became the stepping stone toward Digital
Bangladesh.
Once a single identity links every essential interaction, the convenience it
delivers also carries visibility: the state can see, in one place, what each citizen does. The same
concentration of data also creates opportunities for private actors, whether through commercial
profiling, data exploitation, or unauthorised access, to gain unprecedented insight into individuals'
lives. A concentration of data is therefore not only a criminal's prize but also an instrument of
surveillance and control.
In cybersecurity terms, those who exploit such data are called threat
actors. Although the term typically refers to external adversaries, the same
concentrated data are also, in most cases, lawfully possessed by the state. An enhanced surveillance
capability does not need bad intentions to cause harm because once a single identifier maps individual
identity to activity, it lowers the cost of finding a person, monitoring dissent, and applying pressure
at scale.
Tech Global Institute compiled a dossier of 68 documented breach incidents affecting Bangladeshi
organisations between 2023 and 2026, drawn from four categories of sources: localised threat intelligence
from Bangladesh Cyber Security Intelligence (BCSI); international
dark-web and ransomware monitors (Ransomware.live, Ransomlook.io, RedPacket
Security); threat-alert aggregators (Daily Dark Web on X);
and national dailies including The Daily Star, Prothom Alo, and The Business Standard. For each incident,
TGI logged the data exposed, the vector (where known), who discovered the breach, whether the organisation
acknowledged it, whether any post-mortem followed, and the verification status of the claim.
Details
of the methodology are available in the Appendix.
How incidents are attributed
Attribution follows the data controller: each incident is logged against the institution whose data was exposed, even where the leakage occurred through a partner organisation's authorised access or an insider rather than through a compromise of the institution's own systems. Several incidents linked to the Bangladesh Election Commission are of precisely this kind — citizens' NID data leaking through verification channels operated by private and public entities — and are counted against the country's electoral agency as custodian of the national identity database. The government–private distinction should be read with that convention in mind: it describes where the exposed data lived, not necessarily where the security failure occurred.
With the exception of 2024, breaches were more frequent in the public sector than in the private sector in every year of the covered period.
The targets moved from the state's core to the shop floor.
Neither sector has been spared: a near-even split over the 41-month window means the exposure is systemic, not sectoral.
Reading the numbers
Volume figures originating from criminal sources are the claims of threat actors themselves, and may be exaggerated for extortion purposes. Each incident is therefore tiered by evidentiary strength — see the verification key in the Appendix.
A note on scope
However, these incidents represent only those that could be identified and corroborated through TGI's source matrix and methodology. Additional breaches may have escaped detection, remained confined to private disclosures, or gone entirely unreported. As such, this dataset should be understood as a documented baseline rather than an exhaustive census of breach activity, offering a conservative view of the broader cyber risk landscape rather than a complete accounting of it.
A closer look at the affected entities shows that the overwhelming majority are formally structured organisations — government ministries, regulatory bodies, financial institutions, registered private enterprises, and other entities that maintain large-scale databases containing extensive personal information on citizens — rather than informal or unregistered entities.
While indicative, this pattern should not be interpreted as suggesting that organisational scale alone determines exposure. Rather, it reflects one of several factors that shape cybersecurity risk in an increasingly digitalised economy, where the growing volume and value of data held by public and private institutions, together with extensive digital infrastructure, interconnected systems, and large repositories of PII, make certain organisations particularly attractive targets. At times, the incentive lies not merely in the volume of data, but in its economic or strategic value. For example, institutions connected to overseas employment and inward remittances may hold information on individuals with predictable income flows, making such datasets especially valuable to cybercriminals.
Law enforcement & intelligence agencies · Government ministries · Government banks · Retailers
Government airline · National Parliament of Bangladesh · Bangla Academy · Government educational institution · Private airline · Private educational institution · Media · E-commerce
The electoral agency is linked to at least five incidents: the exposure of NID-linked voter data on Telegram in October 2023; the leakage of citizens' NID data through five partner organisations' verification access in February 2025 — DGHS, Upay, the Chattogram Port Authority, the Department of Women Affairs, and iBAS++, which drew show-cause notices — and two others (Ansar-VDP and BRAC Bank, suspended) in May 2025; the insider syndicate uncovered by the Criminal Investigation Department (CID) in January 2026; and the exposure of roughly 14,000 journalists' accreditation records through a flaw in an agency-run portal days later.
Two features of this record require elaboration. First, in none of these cases has an external intrusion into the agency's central NID database been publicly established; the agency has maintained that its core systems were not hacked, and nothing in our dataset contradicts that. Second, and precisely because of that, the recurring failure mode is the ecosystem built around the database — authorised third-party verification channels, several of them operated by private institutions, and insiders holding valid credentials. The remedy therefore turns less on firewalls and more on access governance, contractual controls, continuous monitoring, and sanctions.
Of particular concern
The National Telecommunication Monitoring Centre (NTMC) is known to intercept phone calls, emails, and social media communications, to collect and retain communication data, to filter and block online content, and to support broader national security and public order objectives through communication intelligence. It reportedly operates a platform through which nearly 500 officials from 42 public organisations are authorised to access citizens' data for verification and investigative purposes. According to reports, the NTMC system was exploited using the credentials of two law enforcement officers to collect and sell — via encrypted messaging services — confidential information, including NID information and mobile call data records, for financial gain. An incident of unauthorised access and data exfiltration and breach involving an agency of this nature is categorically different from a breach at a retailer or news portal as the data it handles is not merely personal or financial, but intercepted communications and surveillance records that, if exposed or misused, could compromise the privacy and safety of individuals being monitored, reveal intelligence methods, or be exploited by malicious actors for blackmail, targeted harassment, or further unauthorised surveillance.
The alleged breach of the database of the Ministry of Expatriates' Welfare and Overseas Employment reportedly compromised passport records, NID information, electronic tax identification number (eTIN) details, and financial and banking documents along with transaction records — identity, tax, and financial information in a single dataset. That combination could be exploited for multiple malicious purposes, including voter manipulation, blackmail, identity-based scams, and financial fraud targeting one of the country's most economically significant demographics.
The appearance of armed forces agencies, ministries, and the Bangladesh Election Commission among breached entities raises the stakes considerably. Unlike commercial breaches, where the primary harm is financial or reputational, breaches in this category carry the potential to escalate into national-security incidents or to directly infringe on citizens' fundamental rights.
This report utilises a descriptive, exploratory mixed-methods design to investigate the landscape of data breaches in Bangladesh between January 2023 and May 2026, combining quantitative content analysis with qualitative thematic analysis to map the frequency, distribution, and systemic patterns of incidents across both public and private sectors. The primary dataset was compiled from 68 documented incidents, aggregated from four categories of sources: localised threat intelligence from Bangladesh Cyber Security Intelligence (BCSI); international dark-web monitoring (Ransomware.live, Ransomlook.io, RedPacket Security); threat-alert aggregators, principally Daily Dark Web; and mainstream media reporting from national dailies including The Daily Star, Prothom Alo, and The Business Standard.
For each recorded incident, we systematically logged eight data points: date; organisation and sector; type of data exposed (as claimed); attack vector (where known); discovery mechanism; whether the organisation acknowledged the incident; whether any post-mortem was published; and the verification status of the claim.
To complement the quantitative findings, we conducted a qualitative policy and legal analysis: a systematic review of Bangladesh's sectoral and general data and identity laws, including the National Identity Registration Act, 2023, and those governing cybersecurity, banking, and telecommunication, together with the Personal Data Protection Act, 2026 and the National Data Management Act, 2026. By tracing the historical progression, we aimed to evaluate the "sequencing gap" between the rapid deployment of digital public infrastructure and the delayed development of rights-protective privacy legislation. This analysis specifically examined, at a high level, how vague provisions, wide executive discretion, and fragmented enforcement mechanisms, rather than a total absence of law, contributed to the systemic vulnerabilities and institutional silence observed in our incident dataset.
Limitations. First, the dataset reflects only reported and discoverable breaches; the true frequency of incidents is almost certainly higher. Second, because we rely on a mixture of official advisories, news reports, and third-party threat-intelligence claims, the volume figures cited are often based on the claims of the threat actors themselves, which may be exaggerated for extortion purposes. We have categorised these findings with confidence tiers distinguishing between verified incidents, reported but unconfirmed events, and unverified dark-web claims to ensure transparency regarding the evidentiary strength of each case. Third, incident narratives are summarised for this report, and where specific data samples are discussed, they are treated in aggregate to maintain the privacy of the victims.
Verification key — the 68 incidents by tier
"Exposed" figures originating from criminal or leak sources are claims, not confirmed counts. Where a field cannot be established from the available evidence it is marked plainly ("Not disclosed", "None published", "No public acknowledgment found").
Showing {{ rowCount }} of 68 incidents