Personal Data for Sale Online in Bangladesh, Exposing Serious Security Gaps
Investigations have found sellers openly advertising access to sensitive information through Facebook, Telegram, WhatsApp and dedicated websites, with buyers allegedly able to obtain different categories of personal data in exchange for money.
The information being offered reportedly includes National ID (NID) records, call detail records (CDRs), mobile phone locations, SMS lists, birth-registration records, passport information, tax identification numbers (TINs), IMEI details and mobile financial service statements.
The reported availability of such information has raised concerns that the problem may extend beyond isolated online fraud and could involve a broader system for obtaining, selling and distributing citizens’ data.
Investigation finds active online market
An investigation by Bangladeshi data and investigative journalism organisation Dismislab identified 10 active websites allegedly involved in selling personal information and hundreds of related advertisements on social media.
A separate follow-up investigation based on the supplied information contacted several numbers published in advertisements and promotional banners. Individuals contacted during the inquiry claimed to offer NID records, call histories and mobile-location information for payment.
Where possible, information obtained during the investigation was independently checked against available details.
The findings suggest that at least some sellers may have access to genuine and potentially current personal information. However, the precise sources of the data and the methods used to obtain it remain unclear.
NID and call records allegedly delivered after payment
Dismislab reported that, in one test, an NID document in PDF format was supplied 17 minutes after investigators provided a mobile phone number and paid 500 taka.
According to the organisation, the document contained the person's name, photograph and date of birth, and those details matched the individual concerned. It also reportedly contained information that had been updated recently.
In another test, investigators paid 1,050 taka for three months of call detail records linked to a phone number. The file was reportedly delivered about two and a half hours after payment.
Dismislab said the recent contact numbers, call times and types of calls contained in the file matched the actual call history when checked.
In a separate test, investigators were reportedly offered mobile-location information within 16 minutes of making a payment. The information allegedly included the most recent active time, a tower-based location, an address and a map location.
If authentic, such information could reveal sensitive details about a person's communications and movements.
Hundreds of social media advertisements
The investigations found that offers to sell personal data were not confined to private communications. Sellers were reportedly using public social media posts, groups and online advertisements to attract customers.
Dismislab said it identified 675 Facebook posts containing a particular search term between June 15 and July 15. Of those, 605 posts reportedly contained offers to sell personal information.
The investigation also identified at least 112 different mobile phone numbers used for communication and found repeated advertisements across 36 active Facebook groups.
The volume and repetition of the advertisements raise questions about whether the activity represents a coordinated market rather than isolated attempts by individual scammers.
However, the existence and structure of any wider network would require further investigation.
The biggest unanswered question: where does the data come from?
Identifying the source of the information is central to understanding the scale of the problem.
Dismislab reported that sellers gave different explanations for how they obtained the data. Some allegedly said they collected information from other online groups or websites.
One seller reportedly claimed to use an API to obtain information from government servers.
That claim has not been independently verified and should therefore not be treated as evidence that government systems have been breached.
Nevertheless, reports that apparently current personal information can be obtained for relatively small payments raise important questions about the security of databases containing citizens' information.
Investigators need to establish whether data is being extracted from government or private databases, obtained through the misuse of authorised access, accessed using compromised accounts or credentials, or exposed through vulnerabilities in software and APIs.
A potential threat beyond privacy
The unauthorised sale of personal information could have consequences far beyond a breach of privacy.
If an individual's NID details, phone number, address, call records, location data and financial information were combined, they could potentially be used to create a detailed digital profile.
Such information could facilitate identity fraud, financial scams, targeted phishing, harassment or unauthorised surveillance. Location information could also potentially expose individuals to physical-security risks.
The danger is therefore not limited to the disclosure of isolated pieces of information. The combination of multiple datasets could make the information significantly more valuable—and potentially more harmful.
Citizens routinely surrender sensitive information
Much of the information reportedly being offered for sale is collected legitimately for essential public and commercial services.
Citizens provide NID information when registering mobile SIM cards and submit identification documents and other personal details when using banks or mobile financial services.
Personal information is also collected through passport applications, birth registration, tax services and land-related transactions.
These institutions therefore carry an important responsibility to protect the information entrusted to them.
Authorities need to trace the full chain
Blocking websites or identifying individual sellers would address only the visible end of the problem.
A more comprehensive investigation should examine the entire chain—from the source of the data and those with authorised access to intermediaries, sellers, buyers and payment channels.
Technical investigations should establish which databases are being accessed, who is accessing them, when the access occurs and whether information is being downloaded or transferred without authorisation.
Organisations holding sensitive citizen data should maintain reliable audit trails showing who has accessed, downloaded or modified records.
Access should also be limited according to employees' roles and responsibilities. Measures such as multi-factor authentication, role-based access controls, regular security audits and vulnerability testing can help reduce the risk of unauthorised access.
Telecommunications data requires particular safeguards
Call detail records and location information are especially sensitive because they can reveal a person's communications, relationships and movements.
Access to such information should be governed by clear legal procedures and restricted to authorised personnel.
Telecommunications operators and other organisations handling such data should also have systems capable of detecting unusual access patterns and potential misuse of authorised accounts.
Ultimately, the central issue is not simply whether personal information is being advertised online. It is whether sensitive data collected for legitimate public or commercial purposes is being diverted into an illicit market.
Determining the original source of the information—and whether the underlying cause is a database breach, misuse of authorised access, compromised credentials or a technical vulnerability—will be critical to preventing further exposure and protecting citizens' privacy.

Comments
Post a Comment