Government Server Data Leak Bangladesh | Rab arrests 5 for allegedly selling personal data from govt servers | The Daily Star

September 13, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thedailystar.net

Threat Risk: High
Victim: Bangladeshi Government and Citizens
Incident: Unauthorized exfiltration and sale of citizen personal and surveillance data from government servers.
Impact: Massive exposure of National ID (NID), birth records, and mobile tracking data, significantly increasing risks of identity theft and targeted surveillance.
Attacker: Unidentified insiders and associated data brokers
Analysis: This incident demonstrates a severe failure in access control and insider threat management within Bangladeshi government infrastructure. The attackers leveraged temporary employment access and a dedicated web portal to commercialize highly sensitive citizen PII and surveillance data. The inclusion of call detail records (CDRs) and IMEI logs suggests deep, unauthorized penetration into state-level databases.
Recommendations: Implement strict Principle of Least Privilege (PoLP) and rigorous offboarding for all temporary and contract staff.; Deploy database activity monitoring (DAM) to alert on anomalous queries of sensitive PII.; Conduct comprehensive audits of administrative access logs for critical government identity and surveillance databases.
Source: The Daily Star

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *