A4Special ReportDooplin Apps S.L.
Special report · Data & privacy
Two Hundred and Fifty Taka
What Bangladesh’s leaked voter rolls, breached banks, and one very quiet supermarket tell us about who is actually guarding your data.
By Sakib Bin Kamal · Co-founder
Barcelona · 8 August 2026
A note before we start: nothing in this report explains how to attack anything. Every incident described here has already been publicly reported, investigated, or prosecuted. The point is not to show anyone a door. It is to point out that we have been leaving them open for a decade and calling it a filing system.
In the weeks after Bangladesh’s 13th parliamentary election on 12 February 2026, the final voter list went on sale.
Not on some unreachable corner of the dark web. On Facebook. The fact-checking outfit Dismislab counted more than 500 posts across at least fifteen accounts, plus at least five paid advertisements — meaning someone gave Meta money to promote the sale of your neighbours’ personal details, and Meta took it.
The pricing was tiered like a mobile data pack. Tk 30–40 for a single constituency. Tk 99 if you came in through the sponsored ad. Tk 250 for the nationwide database. On Telegram, free.
Each record carries a name, a voter number, both parents’ names, a date of birth, an occupation, and a permanent address.
Two hundred and fifty taka is about two US dollars. For two dollars, you can buy the country.
The Election Commission’s response was technically accurate and completely beside the point. Candidates had been given the voter lists in PDF, said the EC’s public relations director, and “the commission had not authorised their sale.” Of course it hadn’t. Nobody authorises this. That is what makes it a systems problem rather than a crime story.
The supermarket that said nothing
Start with the most recent large failure, because it is the cleanest illustration of the whole pathology.
On the afternoon of 19 August 2025, computers at the head office of ACI Logistics — the company behind Shwapno, Bangladesh’s largest supermarket chain, roughly 850 outlets across 63 districts — locked up. The Qilin ransomware crew wanted US$1.5 million and gave a ten-day deadline. The way in, according to subsequent reporting, was the way in almost always is: employees clicking links in phishing emails.
Shwapno refused to pay. That was, on its own, a defensible call. Paying funds the next attack and buys a promise from criminals.
But refusing to pay is only half a decision, and Shwapno appears to have treated it as the whole one.
Modern ransomware crews stopped relying on encryption alone years ago, because companies got better at backups. The business model now is double extortion: copy the data out first, then encrypt what’s left. Restore from backup all you like — they still hold the copy. Publishing it is the second half of the threat, and it is the half that lands on customers rather than on the company. Everyone in the industry has known this since about 2019.
Seven months later, on 17 March 2026, more than 410 GB appeared on the LockBit 5.0 leak portal. Customer names, some two million mobile numbers, around 270 million individual purchase records — the trails of more than four million registered customers — plus supplier contracts, daily sales figures, bank deposit records, HR files, and internal policies. Within days it had spread to Facebook and the open web.
Customers found out from Facebook.
On the night of 28–29 March 2026 — seven months and nine days after the intrusion — ACI Logistics’ head of administration and crisis management lodged a general diary at Tejgaon Industrial police station, naming Qilin and “LockBit 5.0” as accused. It was passed to the Counter Terrorism and Transnational Crime unit. The managing director confirmed the company had not paid, and advised customers not to share personal or financial information with unknown callers.
That advice is correct. It would have been considerably more useful in August.
Why purchase history is not a boring kind of data
Most people hear “shopping data leaked” and shrug. Names and phone numbers, fine, everyone has those. Who cares what I bought?
Purchase history is one of the most revealing datasets an ordinary person generates, precisely because nobody performs for it. You curate what you post. You do not curate what you put in a trolley.
Two hundred and seventy million line items, keyed to a mobile number, tell you who is diabetic and who started buying insulin supplies last spring. Who buys infant formula, and when they stopped. Whose household consumption dropped by half in the month they lost a job. Who buys beef and who never does — in a country where that inference is not neutral. Where someone shops tells you where they live; when they shop tells you when they are out of the house.
And in the immediate term, it is a script. A fraudster who opens a call with “Sir, regarding your order on the fourteenth from the Dhanmondi branch” has already won the part of the conversation that matters. The details are not the payload. They are the credential that gets the payload accepted.
A pattern, not a run of bad luck
Ten years of it, in order:
Feb 2016
Bangladesh Bank
Attackers with a foothold inside the central bank issued around three dozen payment instructions over the SWIFT network, attempting to move US$951 million out of Bangladesh’s account at the Federal Reserve Bank of New York. Malware on the bank’s SWIFT terminal suppressed the printed confirmations that would have raised an alarm. Most transfers were caught; $81 million reached the Philippines and largely evaporated through a casino. The Fed’s position was, essentially, that the instructions were properly authenticated — which was true, and which is the entire problem. The system worked exactly as designed. The design assumed the terminal was trustworthy.
May 2019
Dutch-Bangla Bank
The Russian-speaking crew known as Silence compromised the bank’s card management system and switched off ATM withdrawal limits. Money mules stood at machines taking phone calls and pulling out cash: about US$3 million.
Jun–Jul 2023
The Office of the Registrar General, Birth & Death Registration
Roughly 50 million citizens’ records — names, phone numbers, email addresses, national ID numbers, birth registration details — sitting in the open. It was not a hack. Nobody broke anything. We will come back to this one, because it is the most instructive incident in the set.
Oct 2023 →
The NID data on Telegram
A bot appeared: type in a ten-digit NID number, get back a name, gender, parents’ names, phone number, address, photograph. The Election Commission’s NID server holds identity records for roughly 12 crore (120 million) citizens; about 5.5 crore hold smart cards. The EC suspended data access for some of its 174 partner organisations and put the rest “under watch.”
Apr–May 2024
The monitoring centre
The National Telecommunication Monitoring Centre cut off the Anti-Terrorism Unit’s and RAB-6’s access to its National Intelligence Platform after officials were found to have sold the personal data of some 15,000 people — NID details, call recordings, SIM data — confirmed in a letter dated 28 April 2024 from an NTMC director. Reporting at the time found personal data circulating through 21 WhatsApp groups, 48 Telegram channels, and 720 Facebook groups and pages with a combined 32 lakh members and followers; a permanent address went for Tk 40. Transparency International Bangladesh’s executive director called the government’s data protection efforts “superficial and appallingly risky.”
May–Jun 2024
Agrani Bank
The KillSec group demanded €5,000 — around Tk 6.3 lakh, an insultingly small number — and, when it went unpaid, dumped over 12,000 files on 6 June: office orders, staff provident fund records, loan files, fund disbursement orders, touching some 12,000 clients.
Jan 2026
The CID bust
Investigators announced that more than 365,000 NID records had been sold in a single month at Tk 200–300 each, generating over Tk 10 crore in fraud. Two arrests: an outsourced data-entry operator at the Election Commission in Agargaon, and an office assistant-cum-computer operator at the Gazaria Upazila Election Office in Munshiganj.
Feb 2026 →
The voter roll, Tk 250
Distributed legitimately to candidates in PDF, resold on Facebook — some of it through paid advertisements.
Eight incidents. Four of them involve nobody hacking anything at all.
Four ways this keeps happening
Strip out the specifics and the same four failures repeat.
1 · The data was never locked in the first place
The 2023 birth registration leak was found by Viktor Markopoulos, a researcher at Bitcrack Cyber Security, on 27 June 2023. He was not attacking Bangladesh. He was Googling an SQL error message and the database showed up as the second result. “Finding the data was too easy,” he told TechCrunch. “I wasn’t even intending on finding it.”
What he had actually stumbled onto was an API endpoint — one of the URLs a web application calls behind the scenes to fetch data — that returned birth certificate applications to anyone who asked. Change the number in the request, get somebody else’s record: their email, phone, place of birth, physical address.
Here is the plain-language version. A web application is a building full of doors. Authentication is the lock on the front door: proving you are who you claim. Authorisation is the lock on every interior door: checking that this particular person is allowed in this particular room. The portal had a front door. It had no interior doors at all.
That failure has a name — broken access control — and it has sat at number one on the OWASP Top Ten, the industry’s standard list of web application risks, since 2021. It is the most common serious flaw in web software on Earth. It is also among the cheapest to find: change a digit, read what comes back.
The state minister for ICT at the time, Zunaid Ahmed Palak, was insistent: “No government website has been hacked. Citizens’ information was exposed due to the vulnerability of the website.”
Narrowly, he was right. And it is the least reassuring sentence in this entire report. The distinction between hacked and left open is a statement about how hard the attacker had to work. It is not a statement about your exposure. If anything, it is worse: a hack implies someone had to be good. This required someone to be curious.
2 · There is no doorbell
Markopoulos did the right thing and kept doing it. He emailed BGD e-GOV CIRT — the national computer incident response team — on 27 June. Then again on 28 June, 3 July, 4 July, 5 July, and 7 July. Six emails in eleven days. His first one opened: “I am writing to inform you about a critical security vulnerability that I have recently discovered.” He added, “My motivation lies solely in safeguarding the privacy and security of your citizens.”
Nothing came back. TechCrunch then contacted CIRT, the government press office, the embassy in Washington and the consulate in New York. None responded either.
TechCrunch published on 7 July. On 8 July, CIRT issued a press release noting that it had “promptly” addressed the matter and had “demonstrated its professionalism and expertise by swiftly initiating a thorough investigation.” On 9 July, the data came down — about two weeks after it was first reported.
Read that sequence again. The variable that changed was not the severity of the bug. It was the arrival of a foreign newspaper.
The fix for this costs almost nothing. There is an internet standard, RFC 9116, that defines a plain text file at /.well-known/security.txt containing a contact address for security reports. That is the entire mechanism. A file and a monitored inbox with a human behind it and a rule that every report gets acknowledged within one working day. It is the single cheapest security control that exists, and the country that scored full marks for “technical measures” in an international index does not reliably have one.
Worse: neither the Cyber Security Act 2023 nor the Cyber Security Ordinance 2025 that replaced it in May 2025 carries a clear safe harbour for good-faith security research. So the researcher who finds the open door faces a legal system with no defined space for them to stand in — while the organisation that left it open faces, until 2027, essentially nothing.
3 · The perimeter is not where the risk lives
The 2023 leak did not originate inside the Election Commission’s own fortress. As the EC’s own official explained, one of its partner organisations had stored data it was not supposed to keep.
There were 174 such partner organisations wired into the NID server.
That is the structural fact almost nobody wants to look at. A hundred and seventy-four independent security budgets, hiring standards, patch cycles, and offboarding processes, each holding a live tap into the identity records of 120 million people. The strength of that arrangement is the strength of its weakest participant, and no one is auditing who the weakest participant is.
Then there is the version that requires no software flaw whatsoever. The January 2026 CID case did not involve an exploit. It involved two salaried people with legitimate logins running 365,000 lookups. The NTMC case ended with the monitoring centre revoking the National Intelligence Platform access of the Anti-Terrorism Unit and RAB-6 — that is, two arms of the state’s own security apparatus — after their officials sold some 15,000 people’s records. The voter roll was distributed legitimately to candidates and resold.
The most sensitive identity and communications data in the country was not taken by a foreign adversary. It was retailed by the people issued credentials to protect it.
The technical vocabulary for this is excessive privilege and absent audit logging. The human version is simpler: if any employee can query any citizen’s record, and nobody reviews who queried what, then you have not built an access control system. You have built an honour system with a login page in front of it.
Notice, too, that CID could reconstruct exactly who ran those queries — after Tk 10 crore had already been stolen. The logs existed. Nobody was reading them. Detection that only works retroactively is not detection; it is archaeology.
4 · Denial is the incident response plan
“No government website has been hacked.” — the state minister for ICT, July 2023.
“No hacking happened at our bank.” — the managing director of Agrani Bank, June 2024, after 12,000 clients’ files hit the dark web. Only staff email accounts had been compromised, he explained.
Seven months of silence, then a general diary. — Shwapno, 2025–26.
Each of these statements is a defensive move that makes narrow institutional sense and is disastrous in aggregate, because each one substitutes a debate about labels for the only question that matters to a customer: is my information out, and what should I do about it today?
Every one of these organisations had months in which they could have told people to expect fraud calls, to be sceptical of anyone quoting their NID digits back at them, to change reused passwords. That warning is nearly free and it demonstrably reduces harm. It was not given, because giving it means saying the thing out loud.
A role model, officially
Tier 1 · Role-modelling
Here is where it turns absurd.
In the ITU’s Global Cybersecurity Index 2024, Bangladesh scored 96.96 out of 100 and was placed in Tier 1 — “Role-modelling” — one of eleven such countries in Asia-Pacific, alongside Japan, Singapore, and Australia. It took full marks, 20 out of 20, in three of the five pillars: technical measures, organisational measures, and cooperation. It scored 19.52 on capacity development. Its weakest pillar was legal, at 17.44.
The index is not lying and the people who compiled it did nothing wrong. The GCI measures commitments: laws drafted, agencies constituted, strategies published, agreements signed. It is a measure of institutional intent.
We have been reading it as a report card on outcomes. It isn’t one. You can take full marks for technical measures in the same year an API hands strangers’ birth certificates to anyone who edits a URL, because the index asks whether you have a national CERT — not whether that CERT answers its email.
Meanwhile, the ground truth is available and considerably less flattering. BGD e-GOV CIRT itself identified 25,038 Bangladeshi IP addresses hit by malware over a single year, with financial services, aviation, pharmaceuticals and industry the sectors most exposed to ransomware. A study presented in June 2025 black-box tested 54 private-sector Bangladeshi web applications — universities, hospitals, newspapers, companies — and found that every single one was vulnerable to at least one attack class: 85% leaked information they should not have, 46% were open to cross-site scripting, 40% had broken access control — the exact failure behind the 2023 government leak — and 72% lacked a valid SSL/TLS certificate. In July 2025, Bangladesh Bank’s emergency instruction to the country’s banks and financial institutions, ahead of a publicly announced hacktivist campaign, was to update the patches on their servers and databases.
Patching your servers is not an emergency measure. It is Tuesday.
The law points the wrong way
Bangladesh now has a data protection law. Its journey: gazetted as the Personal Data Protection Ordinance on 6 November 2025, amended by ordinance on 5 February 2026, and enacted by Parliament as the Personal Data Protection Act in April 2026. Enforcement machinery is expected to come fully into force around May 2027.
It contains real things. Citizens get rights of access, correction and erasure. Controllers must notify the authority of breaches likely to cause significant harm. Fines run up to Tk 25 lakh, or Tk 50 lakh for designated significant data controllers.
Now look at the shape of it.
The state largely exempts itself. Section 24 permits processing outside the consent framework on grounds of national security, public order, and crime prevention — terms the ordinance does not define. Sections 50 and 55 let the government direct the authority and order data storage or transfer on grounds of “urgent necessity,” with no judicial oversight in the loop. As one Bangladeshi commentator titled it: a law that protects you from everyone except the state. That is not a rhetorical flourish, given that five of the eight incidents listed above involve government-held data, and two of those turned on government employees selling it.
The regulator reports to the regulated. Members of the governing body are appointed by the government, without a prescribed or transparent process. A data protection authority whose principal offender is also its appointing authority is not a regulator. It is a department.
The penalties are inverted. Suppose the Shwapno breach happened after enforcement begins. Four million people, 270 million records: maximum administrative fine Tk 25 lakh. That is roughly US$20,000: about half a US cent per affected customer, and comfortably less than the security programme that would have prevented the breach. Under the Cyber Security Ordinance 2025, meanwhile, serious offences carry up to ten years’ imprisonment and fines up to Tk 1 crore, and the director general of the National Cyber Security Agency can order material removed or blocked without a judge.
So: four times the maximum financial penalty, plus a decade of prison, attaches to touching a system without permission. A fraction of that, with no custodial exposure and a year’s grace, attaches to leaving four million people’s lives on a server that anyone can walk into.
We have built a system that is expensive to be honest in and cheap to be negligent in. Incentives are not a side issue in security. Incentives are security. Everything else is implementation.
What this costs you, specifically
Set the institutions aside. Here is the arithmetic at your end.
Your NID number, your phone number, your mother’s and father’s names, your date of birth, your permanent address, and — if you shopped at Shwapno — a log of what you bought and when, are all obtainable for a couple of hundred taka.
Those are the same fields used to verify you.
That, in one sentence, is the problem. Bangladesh’s identity infrastructure, its banks, and its mobile financial services all rest on the assumption that someone who knows those details is probably you. That assumption is now false, and it has been false for years, and almost nothing in the verification flow you encounter day to day has been redesigned around that fact.
The consequences are already measurable. Transparency International Bangladesh’s study of the mobile financial services sector found that roughly one in every ten MFS users — 9.3% — has fallen victim to fraud. The CID case turned 365,000 records into Tk 10 crore in a month. As Professor B.M. Mainul Hossain of Dhaka University’s Institute of Information Technology put it regarding the voter roll: criminals can use leaked data to create fake identity cards and apply for services, and it “could also facilitate fraud involving banks and financial institutions.”
The mechanism is boring and that is exactly why it works. Nobody has to break your bank. They only have to sound like they already know you.
Seven things worth doing this week
- Assume your NID number, phone, address and parents’ names are public. Not might be. Are. Stop treating them as secrets — and, more importantly, stop accepting them from others as proof of anything.
- Retire the knowledge test. A caller who recites your NID digits, your branch, or your last purchase has proved nothing. That data is inventory now. If someone must prove who they are, make them do it on a channel you initiated.
- Never move in the direction an inbound caller pushes you. Hang up. Call back on the number printed on your card or shown inside the official app — not the number they give you, and not the one that called. No bank and no MFS provider will ever ask for your PIN or an OTP. There is no verification department, no system upgrade, no emergency that changes this.
- Where an authenticator app is offered instead of SMS codes, take it. SMS can be intercepted or redirected through SIM-swap fraud; a code generated on your phone cannot.
- Give your email account a password you use nowhere else, and turn on two-factor there first. Your inbox is the master key — every “forgot password” flow on Earth terminates there. Use a password manager. It is 2026; memorising passwords stopped being a virtue some time ago.
- Switch on transaction alerts and actually read them. Most account takeovers are visible in the statement well before anyone notices. Detection at your end is the control you fully own.
- Stop handing out NID photocopies on autopilot. Write the purpose and the date across the copy before you give it. Ask what happens to it afterwards. The usual answer — a blank look — is itself the answer.
What would actually fix it
Not aspirational. Things a competent organisation can do this financial year.
If you sit on a board or run a company: stop calling this an IT problem. It is a governance problem with a technical surface.
- Delete more. The cheapest record to protect is the one you no longer hold. Nobody at Shwapno ever decided to keep 270 million line items keyed to mobile numbers; it accumulated because storage was cheap and no one owned the question. Write a retention schedule, give it a named owner, and make sure the deletion job actually runs — then verify that it did.
- Phishing-resistant multi-factor authentication on everything that matters, especially email and administrative accounts. Not SMS.
- Segment the network. One clicked link should not be able to take down a head office. When it can, you have built a studio flat and called it a building.
- Test your backups by restoring them, on a schedule, to a clean environment. A green tick in a console is not a backup.
- Name an accountable executive. A person, with a title, whose performance review includes this. “IT” is not a person.
- Write the breach communication plan while nothing is on fire. Who speaks, what the holding statement says, how customers are contacted, what the 72-hour clock looks like. Every organisation in this report had to improvise it during the worst week of its year, and it showed.
- Publish a
security.txt and monitor the inbox. One file. One rule: every report acknowledged within one working day. - Inventory your third parties. Who currently holds an export of your customer data? Most organisations cannot answer, which means the answer is “more of them than you think.”
If you make policy: the gap is not law. It is architecture and accountability.
- A breach notification duty with a clock, an obligation to the individual and not merely to the regulator, and a penalty that scales with the number of records. A flat Tk 25 lakh ceiling means the fine for four million victims is the same as for four hundred. Fix that and half the behaviour in this report changes on its own.
- A CERT with a published service level. Every report acknowledged, in writing, within one business day. Six unanswered emails should be a resignation matter, not a footnote.
- Statutory safe harbour for good-faith security research. Right now the person who tells you your door is open is exposed and the person who left it open is not.
- Audit the 174. Every query against the NID server should be attributable to a named human, logged immutably, and reviewed continuously — not reconstructed by CID after Tk 10 crore has moved.
- Make the regulator independent, and drop the blanket state exemption. A data protection authority that cannot investigate the government is not protecting data from the largest holder of it in the country.
Two dollars
None of this required a genius.
The 2023 leak was found by a man Googling an error message. The Shwapno breach began with somebody clicking a link in an email. The January 2026 racket ran on the credentials of an office assistant in Munshiganj and an outsourced data-entry operator in Agargaon. The voter roll was not stolen at all; it was handed out and resold. There is no supervillain anywhere in this story.
Which is, if you squint hard, the good news. Ordinary failures have ordinary fixes. Nobody needs to invent anything. Somebody needs to be responsible for it — a named human being whose job depends on the answer, rather than a press release commending its own professionalism while the data is still up.
Until that changes, the going rate holds.
Two hundred and fifty taka. For all of us.
⁂
Publisher’s note · Our own receipts
Dooplin builds software that holds other people’s data, so everything above is also a standard this company has to meet. Where we stand, in checkable form:
- Cognoir tenant documents are never used to train models — ours or anyone else’s. Dated commitment, 4 August 2026, in Standards & Practices, page B2.
- Delete is delete: removal from storage and the search index, not a hidden flag in a database.
- Sitr Shield filters on your device. We never receive browsing history, so there is nothing for us to leak.
- This site runs no trackers and sets no cookies. There is no analytics database to breach.
- As of today,
/.well-known/security.txt is live on dooplin.com. If you find a hole in anything we run, that file says exactly whom to tell — and the change is logged, dated, in Corrections & Notices, page B3.
The cheapest record to protect is the one you never held. We built the company on that sentence before we wrote this report.
← All special reports
Sources
The 2023 government portal leak