ডিজিটাল প্রযুক্তিপ্রতিষ্ঠান পাঠাওয়ের প্রায় ১ কোটি ৯০ লাখ ব্যবহারকারীর ব্যক্তিগত তথ্য নিজেদের কাছে থাকার দাবি করেছে একটি সাইবার অপরাধী চক্র। এসব তথ্য প্রকাশ না করার বিনিময়ে প্রতিষ্ঠানটির কাছে ৪ লাখ মার্কিন ডলার দাবি করেছে তারা। বাংলাদেশি মুদ্রায় এর পরিমাণ প্রায় ৪ কোটি ৮৮ লাখ টাকা।

চক্রটির দাবি, তাদের কাছে থাকা তথ্যের মধ্যে ব্যবহারকারীদের মুঠোফোন নম্বর, ই-মেইল, জাতীয় পরিচয়পত্রের (এনআইডি) নম্বর, ড্রাইভিং লাইসেন্স, অবস্থান, ফেসবুক পরিচিতি ও বাসার ঠিকানা রয়েছে। তবে এসব দাবির সত্যতা স্বাধীনভাবে যাচাই করা সম্ভব হয়নি।

সাইবার নিরাপত্তাবিষয়ক প্ল্যাটফর্ম ডেইলি ডার্ক ওয়েব গত বুধবার সামাজিক যোগাযোগমাধ্যম এক্সে বিষয়টি সামনে আনে। এ সময় ডার্ক ওয়েবে প্রকাশিত একটি পোস্টের স্ক্রিনশটও শেয়ার করে প্ল্যাটফর্মটি।

ডার্ক ওয়েবের ওই পোস্টে দাবি করা হয়েছে, তাদের কাছে পাঠাওয়ের প্রায় ১৩৩ গিগাবাইট তথ্য রয়েছে। এতে প্রায় ২৫ কোটি রেকর্ড ও ৫৯১টি তথ্যভান্ডার রয়েছে বলে উল্লেখ করা হয়েছে। সবচেয়ে বড় তথ্যভান্ডারে ১ কোটি ৯০ লাখ ৬৩ হাজার ৯১৮টি হিসাবের তথ্য থাকার দাবি করেছে চক্রটি।

এ ছাড়া ১ কোটি ৯০ লাখের বেশি এনআইডি নম্বর ও মোবাইল ফোন নম্বর, ১ কোটি ৯০ লাখের বেশি ড্রাইভিং লাইসেন্সের তথ্য, প্রায় ১ কোটি ৯০ লাখ ব্যবহারকারীর ছবি এবং প্রায় ৫৭ লাখ বাসার ঠিকানা তাদের কাছে থাকার দাবি করা হয়েছে।

🇧🇩 BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB DATA EXTORTION, 19M USER RECORDS CLAIMED

A threat actor on an underground forum has posted a public "notice" to Pathao Limited, the Dhaka-based ride-hailing, delivery and fintech super app, claiming to hold its production data and demanding payment

The listing claims:
* ~250 million rows across 591 tables (133 GB)
* A user master table of 19,063,918 accounts with emails, phone numbers, legal names, password hashes, GPS data and Facebook IDs/access tokens
* 19,059,387 National ID (NID) numbers and 19,046,583 driving licence entries, plus profile photos and 5.7M home addresses
* HR records for 549 employees (NID, salary, religion, emergency contacts), 17,943 merchant bank account/routing records and 845,872 direct-debit records
* A 400,000 USDT ransom demand with a 24-hour deadline, and a threat to keep releasing data

The claim has not been independently verified

⚠️ Analyst Note:
The post lists table names and row counts, but the captured page shows no sample records, so the figures cannot be checked. A Pathao claim from what appears to be the same actor first surfaced a day earlier, and the actor says a local newspaper has already reported a service outage; Pathao has not confirmed either. If genuine, national ID, licence and address data at this scale would create serious identity-fraud and SIM-swap risk in Bangladesh. This is an unverified threat-actor claim, NOT confirmation that Pathao was breached. Users should expect Pathao-themed phishing and account-recovery scams and should change any reused passwords

#DDW #DarkWeb #Bangladesh #Pathao #DataBreach #Extortion #ThreatIntelligence #CyberSecurity — Dark Web Intelligence (@DailyDarkWeb) October 7, 2026

🇧🇩 BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB DATA EXTORTION, 19M USER RECORDS CLAIMED

A threat actor on an underground forum has posted a public "notice" to Pathao Limited, the Dhaka-based ride-hailing, delivery and fintech super app, claiming to hold its production data and demanding payment

The listing claims:
* ~250 million rows across 591 tables (133 GB)
* A user master table of 19,063,918 accounts with emails, phone numbers, legal names, password hashes, GPS data and Facebook IDs/access tokens
* 19,059,387 National ID (NID) numbers and 19,046,583 driving licence entries, plus profile photos and 5.7M home addresses
* HR records for 549 employees (NID, salary, religion, emergency contacts), 17,943 merchant bank account/routing records and 845,872 direct-debit records
* A 400,000 USDT ransom demand with a 24-hour deadline, and a threat to keep releasing data

The claim has not been independently verified

⚠️ Analyst Note:
The post lists table names and row counts, but the captured page shows no sample records, so the figures cannot be checked. A Pathao claim from what appears to be the same actor first surfaced a day earlier, and the actor says a local newspaper has already reported a service outage; Pathao has not confirmed either. If genuine, national ID, licence and address data at this scale would create serious identity-fraud and SIM-swap risk in Bangladesh. This is an unverified threat-actor claim, NOT confirmation that Pathao was breached. Users should expect Pathao-themed phishing and account-recovery scams and should change any reused passwords

#DDW #DarkWeb #Bangladesh #Pathao #DataBreach #Extortion #ThreatIntelligence #CyberSecurity

পাঠাওয়ের অভ্যন্তরীণ ও ব্যবসায়িক তথ্য হাতিয়ে নেওয়ারও দাবি করেছে গোষ্ঠীটি। এসব তথ্যের মধ্যে কর্মীদের ব্যক্তিগত তথ্য, প্রশাসনিক প্রবেশাধিকারের নথি, ব্যবসায়ীদের ব্যাংক হিসাব ও ব্যাংকের শাখা শনাক্তকরণ নম্বর, অর্থ লেনদেনের তথ্য, পণ্য সরবরাহের অবস্থান এবং চালকদের যাত্রার নথি রয়েছে বলে পোস্টে উল্লেখ করা হয়েছে।

পোস্টে বলা হয়েছে, তথ্য প্রকাশ না করার বিনিময়ে পাঠাওয়ের কাছে ৪ লাখ ডলার চাওয়া হয়েছে। অর্থ না দিলে এনআইডি, ব্যাংক, কর্মী ও প্রশাসনিক তথ্য প্রকাশের হুমকি দিয়েছে চক্রটি।

এর আগে সেবা বিঘ্নিত হওয়ার বিষয়ে বুধবার (৭ অক্টোবর) পাঠাওয়ের ভেরিফায়েড ফেসবুক পেজে দেওয়া এক বিবৃতিতে প্রতিষ্ঠানটি জানায়, গত ৪ অক্টোবর সাইবার নিরাপত্তাসংক্রান্ত একটি ঘটনা শনাক্ত হওয়ার পর সতর্কতামূলক ব্যবস্থা হিসেবে তাদের কয়েকটি গুরুত্বপূর্ণ সিস্টেম সাময়িকভাবে বন্ধ রাখা হয়েছিল। এতে প্ল্যাটফর্মটির বিভিন্ন সেবা বিঘ্নিত হয়।

বিবৃতিতে পাঠাও আরও জানায়, অল্প সময়ের মধ্যে সেবাগুলো আবার চালু করা হলেও সিস্টেম পুরোপুরি স্থিতিশীল করার কাজ চলছিল। ওই ঘটনায় কিছু ব্যক্তিগত তথ্য দুর্বৃত্তদের হাতে গেছে বলেও প্রতিষ্ঠানটি জানতে পেরেছে। এসব তথ্যের মধ্যে ব্যবহারকারীদের নাম, ই-মেইল ঠিকানা ও মুঠোফোন নম্বর রয়েছে।