Bangladesh Faces Growing Concern Over Online Trade in Citizens’ Personal Data
Investigations have identified offers on Facebook, Telegram, WhatsApp and dedicated websites in which sellers seek payment in exchange for access to highly sensitive personal information.
The data reportedly on offer includes National ID (NID) records, call detail records (CDRs), mobile-phone location data, SMS lists, birth-registration records, passport information, tax identification numbers (TINs), IMEI details and mobile financial service statements.
The apparent ease with which some of the information can be obtained has heightened concerns that the issue may extend beyond isolated online fraud. It could point to a wider ecosystem involving data sources, intermediaries, sellers and buyers.
However, the precise origin of the information—and whether any government or private database has been compromised—has not been established.
Investigation finds evidence of an online data market
Bangladeshi data and investigative journalism organisation Dismislab identified 10 active websites allegedly offering personal information for sale, along with hundreds of related advertisements on social media.
A separate investigation contacted several numbers published in advertisements and promotional banners. People contacted during the inquiry claimed to be able to supply different types of information, including NID records, call histories and mobile-location data, in exchange for money.
Where possible, information obtained through these contacts was checked against available details.
The results indicate that at least some sellers may have access to genuine personal information. But the investigation could not establish how those individuals obtained the data or whether they were connected to any particular institution.
Personal information allegedly delivered within minutes
Dismislab reported one test in which an NID document in PDF format was supplied 17 minutes after investigators provided a mobile phone number and paid 500 taka.
The organisation said the document contained the person's name, photograph and date of birth, matching the details of the individual concerned. It also reportedly included recently updated information.
In another test, investigators paid 1,050 taka for three months of call detail records associated with a phone number. The file was reportedly delivered approximately two and a half hours after payment.
Dismislab said the contact numbers, call times and call types listed in the file matched the actual call history when checked.
A separate test involving location data reportedly produced information within 16 minutes of payment. The material allegedly included the most recent active time, a tower-based location, an address and a map location.
If authentic, such information could provide a detailed picture of an individual's communications and movements.
Hundreds of advertisements identified on Facebook
The reported trade is notable not only because of the sensitivity of the information but also because some sellers appear to advertise their services publicly.
Dismislab said it identified 675 Facebook posts using a particular search term between June 15 and July 15. Of those, 605 posts reportedly offered personal information for sale.
At least 112 different mobile phone numbers were used for contact, while similar advertisements appeared repeatedly in 36 active Facebook groups, according to the investigation.
The volume of posts and contact numbers raises the possibility of a broader commercial network rather than a handful of unrelated sellers.
But the available evidence does not by itself establish how the network operates or whether all of the advertisers have access to genuine information.
The source of the data remains unclear
The most important question is where the information comes from.
Dismislab reported that sellers provided different explanations. Some allegedly said they obtained data from other online groups or websites.
One seller reportedly claimed to use an API to collect information from government servers.
That claim has not been independently verified. There is therefore no basis, on the information available, to conclude that government servers have been breached.
Nevertheless, reports that apparently current personal information can be supplied quickly and for relatively small amounts of money warrant further investigation.
Authorities and affected organisations need to determine whether the data is being obtained from government or private databases, through the misuse of legitimate access, from compromised accounts or credentials, or by exploiting weaknesses in software and APIs.
The risks extend beyond privacy
The unauthorised disclosure of personal information can create risks that go well beyond a loss of privacy.
If NID information, phone numbers, addresses, call records, location data and financial information are combined, they could potentially be used to build a detailed digital profile of an individual.
Such information could facilitate identity theft, financial fraud, targeted phishing, harassment or unauthorised surveillance.
Location data presents an additional concern because it can reveal where a person has been or is believed to be located. In the wrong hands, that information could create risks to personal safety.
The combination of several datasets is particularly concerning because information that may appear relatively harmless on its own can become significantly more sensitive when linked to other records.
Citizens have little choice but to provide such information
Much of the data reportedly being traded is information that citizens routinely provide to institutions in order to access essential services.
NID details are required for services such as mobile SIM registration. Banks and mobile financial service providers also collect identification and other personal information from customers.
Passport applications, birth registration, tax services and land-related transactions similarly require citizens to submit sensitive personal details.
That creates a clear responsibility for organisations handling such information to protect it against unauthorised access, disclosure and misuse.
Closing websites will not solve the underlying problem
The response cannot be limited to shutting down individual websites or identifying people who advertise personal data.
A meaningful investigation would need to trace the entire chain—from the original source of the information to those who obtain it, sell it, broker transactions and purchase it.
Financial transactions associated with suspected data sales should also be examined through appropriate legal channels.
At the technical level, organisations should be able to determine who accessed a database, when it was accessed, what information was viewed or downloaded and whether any unusual activity occurred.
Reliable audit trails are essential for sensitive databases. Access should be restricted according to employees' roles, with stronger controls such as multi-factor authentication, role-based access, regular security audits and vulnerability testing.
Telecom data needs particularly strong protection
Call detail records and location information require especially stringent safeguards because they can reveal an individual's communications, relationships and movements.
Access to such information should be limited to authorised personnel and governed by clearly defined legal procedures.
Telecommunications operators and other organisations holding such data should also have technical systems capable of detecting unusual access patterns and identifying potential misuse of authorised accounts.
Ultimately, the central issue is not simply that personal information is being advertised online. The more important question is how sensitive citizen data is reaching an illicit market in the first place.
If the reported information is genuine and current, identifying its source should be a priority. Whether the cause is a database vulnerability, misuse of legitimate access, compromised credentials or another form of unauthorised disclosure, the underlying weakness must be identified and addressed.
For citizens, the issue is fundamental: information handed over to the state, banks, telecom operators and other service providers for legitimate purposes should not become a commodity available to the highest bidder online.










Comments
Post a Comment