Added to this is the age-old question of repeated data leaks—how weak is the country’s cybersecurity?
Staff Correspondent
A hacker group has claimed to have stolen the personal information and CVs of nearly 6 million Bangladeshi job seekers from BDJobs, one of the country’s leading job platforms. While the company has denied the claim of leaking data from its servers, the incident has brought to the fore an old and worrying question – how prepared are the cybersecurity frameworks of Bangladeshi organizations?
What happened
On Sunday (August 23), a hacker group known as ‘Madrax’ published an advertisement on a website called ‘Dark Forums.ru’. In the post, they claimed that they had millions of CVs of job seekers taken from the BDJobs database, which included names, phone numbers, addresses, emails, educational qualifications, work experience and training information. In support of their claim, the hackers published samples of 148 CVs, which, after analysis, were found to be mostly old information updated between 2011 and 2017.
BDJobs denied the claim, saying that registered employers can view job seeker information through their own accounts, but only for their own recruitment process. It also said that legal action will be taken if any employer sells it to a third party.
This is not an isolated incident—there is a long history of NID leaks.
The BDJobs incident is not the only instance of cybersecurity weakness. In the past few years, there have been multiple incidents of leaks of citizens’ National Identity Card (NID) information from servers of government and private organizations in Bangladesh, raising questions about the country’s overall information security management.
- July 2023: US-based technology media outlet TechCrunch reported that the names, phone numbers, email addresses, and national identification numbers of millions of citizens were leaked through a government agency website in Bangladesh. Cybersecurity expert Sumon Ahmed Sabir warned that such information leaks could put both individuals and organizations at risk of identity theft. However, the Election Commission’s system manager claimed at the time that the main NID server was not hacked, but rather the servers of the service providers may have been hacked.
- October 2023: After the leaked NID data was found on a Telegram channel, the EC said that the data could have been leaked by any of the 174 organizations that had access to the NID server, although the name of the specific organization was not disclosed. It was then revealed that the NID server contains information on 125 million citizens.
- February 2025: The Election Commission Secretary said that NID information was leaked from at least five institutions that had access to verification and that the institutions have been asked to explain how it happened. He also said that it is being investigated whether it was intentional or inadvertent.
- May 2025: The Election Commission temporarily suspends the data verification services of Ansar-VDP and BRAC Bank after receiving credible evidence of NID leaks. An official of the agency said that regular monitoring had found evidence of data leaks from these two institutions.
The notable pattern
A common feature of these incidents is evident: in each case, it is claimed that the main government database itself was not directly hacked; rather, the information was being leaked through weak security measures by third-party organizations (banks, employers, government agencies) that had access to the information. In the case of BDJobs, the company has made the same argument—that information may have been leaked from the accounts of registered employers.
According to cybersecurity analysts, this pattern highlights a structural weakness in Bangladesh’s overall digital infrastructure:
- Third-party risk: When hundreds or thousands of organizations are given access to a central database (NID, BDJobs), each connection becomes a potential weak point.
- Lack of accountability: It takes a long time to identify a leak from a specific organization, and it is often not publicly reported.
- Old information is also risky: As seen in the BDJobs incident, old CVs from 2011-17 can be used for phishing, fraud, or identity theft—the idea that information is safe just because it’s old is wrong.
- Failure to make the results of the investigation public: Although investigations have been announced into multiple leaks from 2023 to 2025, media reports indicate that the full results or determination of liability for any specific incident have not been made public.
Still unresolved questions
It is still unclear about the recent claims regarding BDJobs:
- Was the database really stolen from the main BDJobs server, or was it leaked through a recruiting company account or third party?
- Are all of the claimed 6 million records real, or are only the 148 published samples actually existing?
- The true identity or history of the hacker group called “Madrax”
The report will need to be updated once the results of a formal investigation by the government cybersecurity agency or BDJobs are released.


https://stapravda.ru/20221228/reyting_samyh_populyarnyh_hostingov_v_rossii_196445.html, рейтинг хостингов России подтверждает, что выбор надежного провайдера важен для бизнеса.