Hundreds of posts and ads found on Facebook, data also spreading through Telegram
Voter Lists Sold on Facebook, Personal Data of Millions at Risk
Voter lists prepared for Bangladesh's 13th parliamentary election are being sold on social media. An investigation by Dismislab found that personal information, including names, birth dates and addresses, is being circulated on Facebook and Telegram. Experts warn that the leaked data could fuel financial fraud and cybercrime.
Since May 28, multiple Facebook groups have been offering constituency-based and nationwide voter lists for sale. Prices range from Tk 30 to Tk 60.
An investigation by Dismislab identified more than 500 posts from at least 15 different accounts promoting the sale of voter lists with nearly identical captions.
The lists are also being advertised through paid Facebook ads. Searches in Facebook Ad Library revealed at least five active advertisements offering PDF copies via Google Drive.
Dismislab purchased a nationwide voter database for Tk 250 and received a Google Drive link containing folders for all eight divisions. Verification with known individuals confirmed the authenticity of several entries.
The lists contain names, voter numbers, dates of birth, parents' names, occupations and permanent addresses.
The data is also spreading through Telegram. One group was found sharing voter lists for different constituencies free of charge and announced plans to release photo-based voter databases.
Md Ruhul Amin Mallik, Director of Public Relations at the Election Commission, said the commission had provided PDF copies of voter lists only to election candidates and had not authorized anyone to sell or distribute them.
He suspected that the data might have leaked during printing or copying processes outside the commission.
A seller contacted by Dismislab claimed he had obtained the files from social media.
Professor Dr BM Moinul Hossain, Director of the Institute of Information Technology at the University of Dhaka, warned that leaked information could be used for identity fraud, financial scams, account takeover attacks and other cybercrimes.
He stressed the need for international-standard security practices, regular audits and strict legal action against those responsible for data leaks.
According to experts, institutions should follow the "Need-to-Know Principle" and share only the minimum amount of information necessary for operational purposes.
//DBITECH/DISMISSLAB/DHE//





