$400,000 Ransom Allegedly Demanded

Hackers Claim Pathao Data Theft

  • An unidentified group claims to have stolen 133GB of Pathao data
  • The alleged dataset includes personal and financial information of millions of users
  • Pathao confirmed some customer data exposure but has not verified the broader claims

Hackers Claim Pathao Data Theft
Oct 10, 2026 00:08

An unidentified cybercrime group claims to have stolen 133 gigabytes of data from the information systems of Bangladesh-based technology services company Pathao and demanded a ransom of US$400,000—equivalent to approximately Tk 50 crore? No: approximately Tk 5 crore—in exchange for not publishing the alleged stolen information. The group has reportedly threatened to release more data if Pathao fails to respond within the stipulated period. The claims, however, have not been independently verified, and it remains unclear whether the group possesses the data or controls any of Pathao’s systems.

The allegations surfaced through a screenshot posted on X by ‘Daily Dark Web’, an account that monitors activity on the dark web. According to the screenshot, the alleged database contains around 250 million rows of information stored across 591 tables. The group claims the dataset includes the names, phone numbers, email addresses, password hashes, GPS information, Facebook IDs and access tokens of more than 10.9 million users.

The screenshot also claims the database contains approximately 10.959 million national identity card numbers, 10.946 million driving licence records, and 5.7 million home addresses and profile photographs. No sample records were published to substantiate these claims, making it impossible to verify the alleged volume and nature of the data.

The poster further claims that personal information belonging to 549 Pathao human resources employees was stolen, including national ID numbers, salaries, religion and emergency contact details. The alleged haul also includes information linked to 17,943 merchant bank accounts and routing records, as well as 845,872 direct debit records. An earlier screenshot reportedly claimed the theft of wallet tokens, delivery records, drivers’ login credentials and e-commerce customer information.

According to the post, the unidentified group has demanded 400,000 USDT and asked Pathao to make contact within 24 hours. In return for payment, the group allegedly promised to stop publishing the data, provide encryption keys for locked application nodes and discontinue its malicious activities. There is no independent confirmation that the group has access to the claimed information or control over the relevant systems.

If the claims prove accurate, the incident could pose serious risks to Pathao users’ privacy and financial security. The combination of national ID numbers, phone numbers, home addresses and account-related information could facilitate identity fraud, targeted scams and account takeover attempts. Password hashes and access tokens could create additional risks depending on how they were protected and whether they remain valid.

Pathao’s services experienced disruptions on October 4. The company said some systems had been temporarily shut down following a cybersecurity incident to ensure the security of its platform. Services were subsequently restored.

In a statement issued on October 7, Pathao acknowledged that some customer information—including names, email addresses and phone numbers—had reached malicious actors. The company said it had engaged external cybersecurity experts and informed the relevant authorities. However, it has not confirmed the alleged theft of 133GB of data, the exposure of millions of national ID and driving licence records, or the ransom demand.

Pathao has advised users not to open unfamiliar links or share their passwords, PINs or one-time passwords (OTPs) with anyone. Users who have reused the same password across multiple services should change it and review the security of the affected accounts. They should also contact the relevant service provider promptly if they notice suspicious logins or transactions.

//DBTech/DPB/SME/DPO//