Sensitive citizen records—including National ID cards, passports, phone call logs, and bank details—have leaked repeatedly over the last three years in Bangladesh, with no real accountability or punishment for those responsible.
According to a report by tech research group TechGlobal Institute (TGI), titled “Breached and Unanswered: Bangladesh’s Data Breach Epidemic (2023–2026),” at least 68 major data breaches took place between January 2023 and May 2026.
The findings show that 36 incidents hit government bodies, while 32 targeted private companies. Most organizations had no clue their data had leaked until independent researchers, journalists, or dark web trackers flagged the problem.
Yearly Breakdown
2023: 7 incidents
2024: 27 incidents
2025: 14 incidents
2026 (Jan–May): 20 incidents (13 public, 7 private)
Public utility and government service portals were the worst hit with 20 reported breaches, followed by private corporations and business houses with 16 cases. The Election Commission and telecom providers each saw five breaches, while the armed forces and private financial services recorded three incidents each.
During the study, TGI researchers tested the password recovery system of an official government portal. They uncovered a critical flaw that exposed admin passwords and sensitive citizen data. The issue was immediately reported to BGD e-Gov CIRT, which acknowledged the loophole alongside several other system weaknesses.