Public warned against unauthorized transactions on 'crossmarket.ai'; BFIU opens complaint desk

Bangladesh Bank Red-Flags 22 Payment Aggregators and 31 Illegal Loan Apps

  • Central bank alerts citizens against 22 unlicensed online payment aggregators operating outside regulatory frameworks
  • BFIU red-flags 31 unauthorized lending apps stealing contact lists and sensitive photos to harass and blackmail borrowers
  • Transactions on 'crossmarket.ai' termed punishable offenses under the Payment and Settlement Systems Act, 2024

Bangladesh Bank Red-Flags 22 Payment Aggregators and 31 Illegal Loan Apps
Oct 3, 2026 22:51

Issuing a comprehensive regulatory caution to protect public funds and digital privacy, Bangladesh Bank has warned citizens against transacting with 22 unlicensed online payment aggregators and 31 unauthorized mobile digital lending applications currently operating across the country. The central bank underscored that participating in unapproved financial activities violates statutory regulations and constitutes a punishable offense.

According to a circular issued by the Payment Systems Supervision Department (PSSD), offering payment aggregation services without mandatory institutional licenses directly violates regulatory protocols. The 22 blacklisted aggregators identified by the central bank are: BohudurPay, ZiniPay, PayTiller, BengaliPay, Payora BD, SohojPay BD, EasyPayWay, AK Pay, BD PAY, ShajgarPay, AsthaPay / CPay, UddoktaPay, Walletmix, BttPay, Easy Pay Automation, UniquePay BD, BD AUTO PAY, RH Pay BD, EzePay, AutoPay Ltd, Biswasto, and PipraPay. The monetary regulator strictly advised businesses and consumers to halt all gateway integrations and monetary clearings via these entities.

The central bank previously cautioned the public against illicit deposit-taking operations conducted via an online platform titled ‘crossmarket.ai’. Operating unauthorized deposit and clearing schemes contravenes the 'Payment and Settlement Systems Act, 2024', and the central bank reiterated that unverified participation exposes depositors to financial forfeiture as well as prospective legal complicity.

Simultaneously, investigations by the Bangladesh Financial Intelligence Unit (BFIU) revealed rampant predatory behavior by 31 unauthorized loan apps exploiting social networks. These apps solicit personal device permissions—harvesting user contacts, private photo galleries, and sensitive digital credentials—under the guise of friction-free lending. Once disbursed, operators employ abusive coercive methods, debt-shaming, privacy breaches, and extortionate surcharges, severely threatening individual privacy and domestic financial stability. Under the Money Laundering Prevention Act, 2012, running fraudulent loan systems carries severe punitive implications.

The 31 unregulated lending apps identified by BFIU include: Sathi Loan, PopCash, FinCash, Quick Loan, Quick Taka, Dhaka Fin, LoanVibe, Dost Loan, Taka Cash Loan, Keonja Loan, SSH Money, LoanBuddy, Saathi Loan, CashHero, Alo Cash, Fast Loan, Easy Taka, Dhoirjo Loan, Fin . Do, BongoCash, Asha Loan, Subidha Loan, Smart Loan BD, Online Loan BD, City Online Loan, BD Shohoj Loan, Cash Loan, Sonali, LoanHaat, and TakaNow.

Bangladesh Bank has outlined four critical security directives for consumers:

  1. Strictly refrain from soliciting micro-loans from unverified web portals or mobile apps;

  2. Avoid engaging in unauthorized lending schemes tied to fraudulent layering and money laundering;

  3. Never share National Identity Card (NID) credentials, banking tokens, or phone storage access with unknown APKs;

  4. Desist from remitting advance registration costs or undocumented processing fees to lenders.

Victims of fraudulent operations or individuals with verified intelligence are urged to submit formal reports through the BFIU official web portal or directly to the Office of the Director, BFIU, at Bangladesh Bank Headquarters in Motijheel, Dhaka.

//DBTech/CTR/A=SMP/BPC//