Bangladesh suffered at least 68 documented data breaches between January 2023 and May 2026, exposing sensitive information ranging from national identity numbers and passport details to biometric and financial records, according to a new investigation that warns of systemic failures in protecting citizens’ data.
The report, published by the Tech Global Institute (TGI), documented 36 incidents involving government organizations and 32 involving private entities, suggesting that weaknesses in data protection extend across both sectors.
Titled Breached and Unanswered: A Cartography of Bangladesh’s Data Breach Epidemic, the investigation found that most breaches were discovered not by the affected institutions but by outside cybersecurity researchers, media organizations, dark-web monitoring services and threat-intelligence platforms.
Only two cases in the dataset involved institutions detecting problems themselves — the Election Commission identifying leaks within its identity-verification ecosystem and a police investigation into an alleged breach. In most other cases, the researchers found little evidence of public acknowledgment, forensic investigation or publication of a post-incident assessment.
The findings are particularly significant because Bangladesh has rapidly concentrated citizens’ personal information within interconnected digital systems. The country's smart national identity cards can contain fingerprints, iris scans and dozens of categories of personal information, while the NID system has become central to banking, telecommunications, government services and other everyday transactions.
TGI recorded seven breaches in 2023, followed by 27 in 2024 and 14 in 2025. Another 20 incidents were documented in just the first five months of 2026. Government institutions accounted for more incidents than private organizations in every year except 2024.
The Election Commission, which oversees Bangladesh's national identity database, was linked to at least five incidents in the dataset. TGI stressed that there was no established evidence that the Election Commission's central NID database itself had been hacked.
Instead, the incidents exposed weaknesses in the wider ecosystem through which other organizations and authorized users can access identity information. These included leaks involving third-party verification channels, insiders with legitimate credentials and a vulnerable portal.
Among the most serious cases examined was an alleged compromise involving the National Telecommunication Monitoring Centre, or NTMC, which handles sensitive communications and surveillance information.
According to reports cited by TGI, credentials belonging to two law enforcement officers were exploited to obtain confidential information, including NID information and mobile call records, which was then allegedly sold through encrypted messaging platforms.
The researchers warned that breaches involving such an institution carry risks beyond conventional identity theft because compromised surveillance information could potentially facilitate blackmail, harassment or further unauthorized monitoring.
The report also highlighted repeated targeting of databases containing information on Bangladeshi migrant workers.
Databases associated with the Ministry of Expatriates' Welfare and Overseas Employment, overseas-worker platforms and the Bureau of Manpower, Employment and Training were reportedly hit three times in roughly six weeks between April and May this year.
The compromised or allegedly compromised information included passport records, NID details, electronic tax identification information, banking documents and transaction records. Claims surrounding some breaches, however, originated from criminal groups and could not be independently verified.
TGI said such information could make migrant workers particularly vulnerable to phishing, financial fraud and identity theft because criminals could combine personal, financial and overseas employment information to construct convincing scams.
The researchers also examined Bangladesh's legal framework and found what they described as a persistent accountability gap despite successive cybersecurity and data-protection laws.
The Personal Data Protection Act, 2026 introduced a statutory breach-notification requirement, but TGI said notification is required only when an incident is likely to cause "significant damage," while details including the timeframe and form of notification have been left for future regulations.
The report also questioned whether penalties of up to Tk 5 million would provide sufficient deterrence for organizations controlling databases containing information on millions of people.
Researchers warned that the National Data Management Act, 2026 could further increase risks by expanding database interoperability and centralized data infrastructure without sufficiently strong accountability mechanisms.
TGI said it found no publicly reported precedent-setting prosecution establishing institutional accountability for a major data breach across nearly eight years of Bangladesh's cybercrime legislation. Arrests or access suspensions occurred in some cases, but researchers found little evidence of broader institutional reforms following breaches.
The institute cautioned that its 68 incidents should be considered a baseline rather than a complete tally. Of them, 32 were classified as verified, five as reported but unconfirmed and 31 as unverified claims originating primarily from leak sites or dark-web forums.
The actual number could therefore be considerably higher, as breaches may remain undetected or never become public.
During preparation of the report, TGI researchers said they encountered another example of the vulnerabilities they were documenting. A malfunctioning password-recovery page on a government portal exposed an internal configuration file containing administrative database passwords, cryptographic keys and government email credentials.
The researchers reported the vulnerability to Bangladesh's government computer incident response team, which acknowledged the report and identified additional security gaps.
TGI concluded that Bangladesh's central cybersecurity problem was not necessarily the sophistication of its attackers but weaknesses in basic institutional security practices.
As government and private services become increasingly interconnected, the report warned, failures in access controls, security auditing and monitoring could leave ever larger quantities of citizens' information exposed.
“The exposures documented in this report are attributable not principally to exceptionally capable adversaries,” the researchers said, but to preventable failures in governance, security engineering and operational discipline.
—