Data Leak Rises While Accountability Lacks
68 Government and Private Data Leaks in Three Years
- Institutional weaknesses expose citizens sensitive data on Darkweb
- High levels of corruption exist in the utility and public service sectors due to a severe lack of institutional monitoring and efficiency
- Cybersecurity gaps endanger millions of citizens sensitive data
At least 68 data breach incidents involving sensitive citizen information, including National Identity Cards (NID), passports, call records, and bank accounts, occurred over the past three years. Most institutions responsible for data security were unaware of the breaches beforehand. In many cases, external cybersecurity researchers, media outlets, or dark web monitoring firms identified the leaks. However, meaningful accountability or penalties remained extremely limited, according to relevant sources on August 23, 2026, Sunday.
These findings were revealed in a report titled "Breached and Unanswered: Bangladesh's Data Breach Epidemic (2023–2026)" by TechGlobal Institute (TGI). The report documented at least 68 incidents between January 2023 and May 2026, involving 36 public and 32 private organizations.
The report was authored by cybersecurity and data governance researchers Shahnawaz Patwari, Shahzeb Mahmood, Kalim Ahmed, Apon Das, and Fawzia Afroz. According to TGI, seven incidents were recorded in 2023, 27 in 2024, 14 in 2025, and 20 in the first five months of this year, comprising 13 public and seven private organizations.
The report noted that public institutions saw more breaches in most years except 2024. Public services and utility providers accounted for the highest number at 20, followed by private corporations at 16, Election Commission-related entities at five, telecom and internet providers at five, armed forces at three, and private banks and MFS providers at three.
Fawzia Afroz, Bangladesh Lead at TGI, claimed that protecting citizen data is a state responsibility, but clear gaps in structure, law, and accountability increase the risk of misuse.
During the research, TGI researchers tested a password recovery mechanism of a government portal and found a flaw that exposed administrative passwords and sensitive data. The issue was reported to BGD e-GOV CIRT, and TGI stated that authorities acknowledged the vulnerabilities.
A major observation was the limited internal breach detection capacity. External researchers or media identified breaches first. TGI stated that most entities lacked 24/7 security monitoring.
Election Commission-related systems faced at least five incidents between 2023 and 2026. While no direct intrusion into the main NID database was found, third-party verification channels were vulnerable. In January 2026, CID exposed a syndicate selling 365,000 NID records in one month.
In 2024, allegations surfaced against two police officers selling sensitive personal data accessed via National Telecommunication Monitoring Center (NTMC). TGI highlighted this due to involvement with surveillance data.
Around 500 officials across 42 government agencies hold data access, raising risks of misuse. Vulnerabilities were also identified in the Ministry of Expatriates Welfare database, exposing passport, NID, and banking records of over one million workers. TGI claimed three breach attempts occurred within six weeks in April and May 2026.
National Cyber Security Agency (NCSA) monitors 36,000 domains. NCSA Director General Tayebur Rahman claimed that hosting has been moved to Bangladesh Data Center Company Limited (BDCCL) with multi-layer security being implemented. He added that a shortage of skilled technical personnel poses a significant risk.
TGI noted that despite numerous breaches, legal actions remain scarce. Under the Personal Data Protection Act 2026, breach notification is mandatory, but TGI expressed concerns over broad exemptions for state bodies.
Researchers concluded that breaches stem mostly from weak administrative discipline rather than sophisticated attacks, recommending reforms including Secure-by-Design models, Zero Trust Architecture, and 24/7 SOC operations.
//DBTech/Nafiza Anzum/IH//





