Staff Reporter:
An online black market for citizens’ personal data has emerged across Bangladesh, with sensitive information being openly traded through Facebook advertisements, websites, Telegram, and WhatsApp, according to an investigation by fact-checking and digital media research initiative Dismislab.
The report, titled “Almost everything about You, for sale,” reveals that National Identity (NID) cards, Call Detail Records (CDRs), live mobile location data, SMS logs, Tax Identification Numbers (TINs), passport information, and Mobile Financial Service (MFS) statements are readily available for purchase.
Researchers identified 10 active websites selling personal data and tracked over 600 related advertisements on Facebook within a single month.
While investigating the illicit sale of voter lists in June, Dismislab uncovered advertisements offering personal data in social media comment sections. A targeted search for the phrase “sign copy”—a term commonly used by illicit data traders—returned 675 posts. Of those published between June 15 and July 15, 605 explicitly offered personal data for sale.
To verify the operation, Dismislab researchers posed as buyers and contacted an advertiser in a Telegram group named “Voter List.” After providing a target mobile phone number and paying Tk 500, they received a PDF copy of the subscriber’s NID within 17 minutes. The name, photograph, date of birth, and other details precisely matched the actual SIM card owner. Even recent updates—such as a correction to the owner’s mother’s name made just two months prior—appeared in the leaked document.
The investigation uncovered an extensive underground ecosystem. Within the same Telegram group, an account operating under the handle “Help BD” advertised a wide spectrum of compromised records, including birth and death registrations, real-time mobile locations, CDRs, SMS histories, phone IMEI numbers, TINs, police clearance certificates, passport copies, and land development tax receipts.
On June 25, Dismislab tested the service by requesting three months of call records for a Grameenphone subscriber. Upon transferring Tk 1,050, researchers received the complete file within two and a half hours. A cross-verification of the 20 most recent contact numbers, call times, and call types against the subscriber’s actual log confirmed 100 percent accuracy.
Location tracking services proved equally accessible. On another website, researchers requested the real-time position of a mobile number. Within 16 minutes of payment, the seller provided the subscriber’s latest active time, cell tower-based location, physical address, and a direct Google Maps link.
A multi-layered market
Dismislab’s findings indicate a highly structured market operating across multiple platforms, utilizing at least 112 unique contact numbers across 36 active Facebook groups.
Most sellers on social media do not hold primary access to the database leaks. Instead, they operate as middlemen, purchasing records from underlying networks and reselling them at a markup.
The owner of one data-vending website based in Chandpur told Dismislab that he buys a subscriber’s call records for Tk 800 and resells them for Tk 900, adding that complete bKash financial statements can be procured for Tk 4,500.
The vendor claimed his primary source retrieves records via an Application Programming Interface (API) link that exploits security vulnerabilities in government servers. Dismislab noted it could not independently verify the API breach claim.
The investigation found that advertisements for personal data have been circulating online since 2023, with promotional content appearing on YouTube as recently as March 2025.
Cybersecurity experts warned that compromised call detail records pose severe privacy and security risks. CDRs detail call durations, timestamps, recipient numbers, device IMEI codes, and tower locations. Aggregated over time, this data allows bad actors to map an individual’s personal relationships, daily routines, and movement patterns.