# Breached and Unanswered — Tech Global Institute > Canonical URL: https://investigations.techglobalinstitute.com/ ## Report **Title:** BREACHED AND UNANSWERED — A Cartography of Bangladesh's Data Breach Epidemic **Publisher:** Tech Global Institute **Coverage period:** January 2023 – May 2026 ## Abstract Between January 2023 and May 2026, at least 68 data breach incidents affecting both government institutions and the private sector appear to have occurred in Bangladesh. Drawing from cybersecurity advisories, dark-web monitoring services, threat-intelligence feeds, and mainstream newspapers, the report finds that 36 incidents involved government organisations and 32 involved private ones. Exposed data includes national identity numbers, biometric records, passport details, and other personally identifiable information. A central finding is institutional blindness: almost all documented cases were identified by external security researchers, news outlets, or dark-web monitoring services rather than by the affected organisations themselves. ## Headline statistics - **68** documented incidents (Jan 2023 – May 2026) - **36** government / **32** private sector - **Verification tiers:** 32 verified · 5 reported, unconfirmed · 31 unverified claims - **Eight data points** logged per incident: date; organisation and sector; type of data exposed; attack vector; discovery mechanism; acknowledgment; post-mortem; verification status ## Key affected-entity categories (approximate distribution) 1. Government services and utility providers — 20 incidents 2. Private companies and business groups — 16 incidents 3. Bangladesh Election Commission–linked — 5 incidents 4. Telecommunication and internet service providers — 5 incidents 5. Armed forces — 3 incidents ## Four interlocking legal deficiencies (Personal Data Protection Act, 2026 context) 1. **Broad exemptions provided to the state** — wide public-sector processing exemptions with weak independent oversight and accountability for public bodies that are the largest collectors of personal data. 2. **The remedies are not yet switched on** — delayed commencement leaves enforcement and breach-notification obligations in abeyance during the transitional period. 3. **Regulator-centred, not victim-centred** — no independent civil cause of action for affected individuals; compensation mechanism lacks defined parameters; administrative penalties may be insufficient for population-scale data controllers. 4. **A parallel law widens the surface area** — the National Data Management Act, 2026 expands mandatory database integration and centralised data governance, increasing exposure without robust accountability mechanisms. ## Authors Apon Das (Researcher) · Mir Rownak (Research Associate) · Kalim Ahmed (Research Manager) · Shahnewaj Patwari (Fellow) · Fowzia Afroz (Country Head, Bangladesh) · Shahzeb Mahmood (Head of Research) ## Machine-readable data Full incident appendix (68 records): https://investigations.techglobalinstitute.com/data/incidents.json