❐ Staff Reporter
A group has said that they have the information of about 20 million (19 million) users of digital technology company Pathao.
According to the group, this information includes users’ mobile phone numbers, e-mails, National Identity Card (NID) numbers, driving licenses, locations, Facebook profiles, and home addresses.
The sender has been asked for $400,000 on the condition that the information not be disclosed.
Cybersecurity platform Daily Dark Web posted about the claim on social media platform Xe (formerly Twitter) on Wednesday, October 7. The post also included a screenshot of the claim made on the dark web.
Pathao’s services were disrupted on Wednesday. In this context, the company said that after a cybersecurity incident was detected on October 4, they temporarily shut down some important systems as part of a precautionary measure. As a result, various services on the platform were disrupted. Although the services were restored within a short time, work is still underway to fully stabilize the system.
A statement on Pathao’s verified Facebook page on Wednesday said that some critical systems were temporarily shut down as a precautionary measure after a cybersecurity incident was detected on October 4th.
The company learned that during the incident, some personal information, including names, email addresses, and phone numbers, fell into the hands of criminals.
The statement also said that they have taken immediate measures to control the situation and have engaged cybersecurity experts to strengthen security.
The post on the dark web claims to have about 133 gigabytes of Pathao data. It states that it contains about 250 million records and 591 databases. The largest database contains information on 19 million 63 thousand 918 accounts.
The group also said that they have more than 19 million NID numbers and mobile phone numbers and more than 19 million driving license information. In addition, they have claimed to have photos of about 19 million users and about 5.7 million home addresses.
The group said it also had access to Pathao’s internal and business information, including employee information, administrative access records, merchants’ bank account and branch identification numbers, financial transaction information, product delivery location information, and driver journey records.
The post demands $400,000 from the sender, threatening to reveal NID, bank, employee, and administrative information if the money is not paid.
In this context, cybersecurity expert Tanvir Hasan Joha said, “The relevant organization needs to conduct a rapid independent digital forensic investigation to verify the matter. In addition, all relevant digital evidence, including servers and access logs, must be preserved and reported to regulatory and law enforcement agencies as per the law.”
According to him, the highest priority should be given to preserving digital evidence, ensuring the security of citizens’ personal information, and taking legal action based on evidence.
It was not possible to contact Fahim Ahmed, the Chief Executive Officer (CEO) of Pathao, to inquire about the matter.



https://stapravda.ru/20221228/reyting_samyh_populyarnyh_hostingov_v_rossii_196445.html, рейтинг хостингов России подтверждает, что выбор надежного провайдера важен для бизнеса.