A national identity card can be obtained in 17 minutes. A mobile subscriber’s latest location can arrive in 16 minutes. Three months of call records can be delivered within a few hours.

In Bangladesh, sensitive personal information that is supposed to be protected is being openly bought and sold online.

An investigation by Dismislab found an expanding market where sellers advertise personal data on Facebook, process orders through websites and communicate with buyers through Telegram and WhatsApp. Payments are made through mobile financial services including bKash and Nagad.

The information on offer includes national identity cards (NID), call detail records (CDR), recent mobile locations, SMS lists, passport information, tax identification numbers, birth and death registration records, police clearance certificates and land development tax receipts.

Prices are published or quoted in advance, and in many cases a buyer needs to provide only a mobile number or NID number.

Dismislab found more than 600 Facebook posts advertising personal information during a one-month search between Jun 15 and Jul 15. It also identified 10 active websites selling such data.


The investigation purchased CDRs, recent location information and NID data from three sellers, paying through bKash. The information was subsequently verified with the individuals concerned by Dismislab and found to be accurate.

NID in 17 Minutes

The investigation began after Dismislab researchers came across Facebook posts advertising the sale of voter information.

A search for the term “sign copy” produced 675 Facebook posts published between Jun 15 and Jul 15. Of these, 605 were advertisements for personal information.

A “sign copy” contains extensive NID and voter information, including a person’s name, photograph, date of birth, parents’ names, educational qualifications, marital status, occupation, address, voting area, religion, physical identification marks and signature or thumbprint information.

Sellers also use the term “server copy” for a PDF carrying the Election Commission’s logo and detailed NID information.

One Facebook lead took Dismislab to a Telegram group called “Voter List”, where an account using the name “Shibat Zubar” advertised a service to obtain an NID using a mobile number.

Posing as a buyer, a Dismislab reporter provided a mobile number belonging to a consenting subscriber and paid Tk 500 in advance.

Within 17 minutes, the seller sent a PDF copy of the subscriber’s NID. Dismislab found that the name, photograph, date of birth and other information matched the actual SIM owner. Even the subscriber’s mother’s name, which had been corrected two months earlier, appeared in its updated form.

A second test produced similarly accurate information.

Another seller, operating under the account name “Help BD”, offered NID “sign copies” and “server copies” as well as birth and death registration records, mobile locations, CDRs, SMS lists, IMEI numbers, TIN certificates, passport copies and land development tax receipts.

After receiving Tk 150 along with a voter number and date of birth, the seller supplied an accurate NID PDF. In another test, a “sign copy” linked to a mobile number was obtained for Tk 250.

Call Records and Movements

Dismislab then ordered three months of call detail records for a Grameenphone number.

After receiving Tk 1,050, the seller delivered the file within two and a half hours.

The most recent 20 contact numbers, call times and call types in the file were checked against the subscriber’s actual phone history. All matched.

CDRs can reveal who a person communicated with, when the communication took place, its duration and whether a call was incoming or outgoing. They can also contain the IMEI number identifying the handset and the IMSI number identifying the SIM.

The records include the mobile tower or network cell area associated with a call or SMS. Analysing such information over a longer period can therefore help establish patterns in a person’s movements.

Dismislab also identified a website operated by a mobile phone repair technician in Chandpur. After payment, the site supplied the recent active time and tower-based location of a Grameenphone number within 16 minutes, along with an address and a Google Maps link.

A Market Operating in Layers

Dismislab found at least 112 distinct mobile numbers used to advertise or facilitate the sale of personal information across the Facebook posts it examined.

One Grameenphone number appeared in 75 advertisements. Ten separate mobile financial service numbers were found across the 10 websites.

The advertisements appeared repeatedly in 36 active Facebook groups. Seven of those groups had at least five such posts each, with 114 promotional posts found across them.

The findings came from searching a single social media platform using just one keyword — “sign copy” — suggesting that the actual size of the market could be considerably larger.

The market appears to operate through several layers.

At the lower level, sellers advertise on social media and take orders from customers. They then use websites to purchase the requested information, paying through services such as bKash, Nagad, Rocket or Upay. The information is subsequently resold to customers through social media, WhatsApp and Telegram at a higher price.

A website owner in Chandpur told Dismislab that he bought call lists for Tk 800 and sold them for Tk 900.

He also claimed that for Tk 1,000 he could provide the NID used to open a bKash account and, for Tk 4,500, obtain the account statement.

Dismislab could not independently verify whether bKash transaction statements could actually be obtained in this way.

Following publication of the investigation, bKash rejected the claim.

Its Head of Corporate Communications Shamsuddin Haider Dalim said account statements are provided only to customers after identity verification, while designated officials and law enforcement agencies can obtain them in specific circumstances under legal procedures.

The Chandpur website owner also claimed that some information was being obtained by bypassing government servers through an application programming interface, or API.

Dismislab could not independently verify the technical accuracy of that claim or the identities of the people the website owner said supplied the information.

Who Has Access?

Call detail records and basic subscriber location information are held by mobile operators.

Grameenphone said it prioritises the protection of subscriber information and provides it only to authorised individuals in accordance with applicable laws, regulatory guidelines and approved standards.

Robi Axiata said CDR, SIM registration and location-related information is provided only to government agencies authorised under the law and through established procedures.

However, a senior official at a mobile operator told Dismislab that more than 10 law enforcement agencies, including the Bangladesh Telecommunication Regulatory Commission (BTRC), National Telecommunication Monitoring Center (NTMC) and police headquarters, have access to several important systems belonging to the operator.

According to the official, this access allows authorised agencies to view detailed call records and information used for SIM registration.

The official, speaking anonymously, said the operator had investigated the source of some leaks and found that information was being extracted through the API of a government law enforcement agency.

The operator said action had been taken against several officials after the authorities were informed and that the BTRC had been notified several times.

Sumon Ahmed Sabir, chief technology officer at Fiber at Home, said real-time information could only be obtained by someone with access to the relevant institutional systems or through a security loophole.

“No one but an insider at the relevant institution can provide real-time information,” he said, adding that the market indicated either the involvement of people with database access or exploitation of vulnerabilities unknown to data custodians.

Warnings, Complaints — But No End to the Trade

Dismislab found evidence that the trade has been operating openly since at least 2023.

A YouTube search also found a video published in March 2025 advertising a similar service.

One mobile operator said it had previously submitted a complaint to the authorities with evidence of the data sales, but the practice had continued.

Col Md Kamrul Hasan Mamun, a senior BTRC official, said the home ministry had formed a committee roughly two months earlier to examine the issue.

The committee reviewed the matter and sent a letter to the ministry, which subsequently forwarded it to the BTRC and other relevant institutions with instructions to investigate. Some law enforcement agencies were also informed.

Mamun said he expected a decision within the following month or two.

Dismislab also found that the NTMC had written to the Ministry of Home Affairs in April 2024 over the sale of citizens’ NID cards and call records.

According to a news report cited by Dismislab, the NTMC letter said such information was being sold in 789 social media groups. An investigation reportedly found that data had been accessed using login credentials and passwords belonging to officials from the Anti-Terrorism Unit and RAB-6. A cybercrime constable also admitted involvement in selling sensitive call records for money.

Sabir said the National Cyber Security Agency has a responsibility to monitor whether institutions handling sensitive information are maintaining adequate security.

He also questioned whether employees responsible for handling such information sufficiently understand that leaking it could violate citizens’ privacy.

“In many cases, an employee may not even think that this is confidential data, that it cannot be leaked and that doing so could violate someone else’s privacy,” he said.

The NCSA’s director general, Md Taibur Rahman, initially agreed to an interview. Questions were later sent to him over WhatsApp with his consent, but he did not respond to Dismislab before publication.

The Election Commission, National Identity Registration Wing and NTMC were also contacted for comment. The Election Commission requested a written application, while questions sent to the director general of the National Identity Registration Wing went unanswered. An NTMC official declined to comment, and a subsequent interview request to the agency’s additional director also went unanswered.

What Happens When Your Data Leaks?

The risks extend well beyond privacy.

Sabir said NID information is particularly sensitive because it is widely used as a means of identity verification.

Someone possessing comprehensive NID information could potentially impersonate another person, create fraudulent accounts or conduct transactions in that person’s name.

The combination of NID information with call records, location data or financial information could increase those risks further.

A person’s location history, for example, can reveal movement patterns, while call records can expose their communication networks.

The Electronic Privacy Information Center, a US-based research organisation, has also documented how information held by data brokers can create different risks for groups including survivors of domestic abuse, immigrants and government officials.

Bangladesh’s Personal Data Protection Act, 2026, provides that personal data collected for a specific purpose cannot be disclosed for another purpose without the individual’s consent. It also allows affected individuals to complain to the relevant authority when their rights are violated.

The law includes administrative fines for failures relating to data protection and security, with penalties in some cases reaching Tk 2.5 million.



Contact
reader@banginews.com

Bangi News app আপনাকে দিবে এক অভাবনীয় অভিজ্ঞতা যা আপনি কাগজের সংবাদপত্রে পাবেন না। আপনি শুধু খবর পড়বেন তাই নয়, আপনি পঞ্চ ইন্দ্রিয় দিয়ে উপভোগও করবেন। বিশ্বাস না হলে আজই ডাউনলোড করুন। এটি সম্পূর্ণ ফ্রি।

Follow @banginews