Bangladesh government website leaks citizens’ personal data - Bangladesh HR Defender | Human Rights, Rule of Law & Accountability

Latest

Monday, July 10, 2023

Bangladesh government website leaks citizens’ personal data

Security

Bangladesh government website leaks citizens’ personal data

a photo of a Bangladeshi national ID card held up to the camera (with identifying data blurred)Image Credits: Munir uz Zaman / AFP / Getty Images

A Bangladeshi government website leaked the personal information of citizens, including full names, phone numbers, email addresses and national ID numbers.

Viktor Markopoulos, a researcher who works for Bitcrack Cyber Security, said he accidentally discovered the leak on June 27, and shortly after contacted the Bangladeshi e-Government Computer Incident Response Team (CIRT). He said the leak includes data of millions of Bangladeshi citizens.

TechCrunch was able to verify that the leaked data is legitimate by using a portion to query a public search tool on the affected government website. By doing this, the website returned other data contained in the leaked database, such as the name of the person who applied to register, as well as — in some cases — the name of their parents. We attempted this with 10 different sets of data, which all returned correct data.

TechCrunch is not naming the government website because the data is still available online, according to Markopoulos, and we haven’t heard back from any of the Bangladeshi government organizations that we emailed asking for comment and alerting of the data exposure.

In Bangladesh, every citizen aged 18 and older is issued a National Identity Card, which assigns a unique ID to every citizen. The card is mandatory and gives citizens access to several services, such as getting a driver’s license, passport, buying and selling land, opening a bank account, and others.

Bangladesh’s CIRT, the government’s press office, its embassy in Washington, D.C. and its consulate in New York City did not respond to requests for comment.

Markopoulos said finding the data “was too easy.”

“It just appeared as a Google result and I wasn’t even intending on finding it. I was Googling an SQL error and it just popped up as the second result,” he told TechCrunch, referring to SQL, a language designed for managing data in a database.

The exposure of email addresses, phone numbers and national ID card numbers is bad on its own, but Markopoulos said that having this type of information could also “be used in the web application to access, modify, and/or delete the applications as well as view the Birth Registration Record Verification.”

Additional reporting by Jagmeet Singh.

Correction: a previous version of this story referred to the Bangladeshi e-Government Computer Incident Response Team with the acronym CERT. In fact, the correct acronym is CIRT. 


Do you have information about similar leaks or data breaches? We’d love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

TechCrunch


Endless gratified thanks for reading/watching/listening

No comments:

Post a Comment

Please validate CAPTCHA

HR Defender App Icon
Official Android App

HR Defender

Human Rights • Rule of Law • Accountability

Install the official HR Defender mobile app for faster access to human-rights analysis, governance commentary, public-interest writing, and policy insights from Bangladesh and beyond.

Fast Mobile Access Policy & Rights Commentary Android App Version 1.0
APK download • Android installation required
HR Defender App Screenshot
Why install the HR Defender app?
✔ Faster reading experience ✔ Direct policy access ✔ Clean mobile interface ✔ Easy Android installation

What You Get

01
Mobile Access

Open Bangladesh HR Defender quickly on your Android phone without typing the website address each time.

02
Policy Reading

Read human-rights analysis, governance commentary, and public-interest policy content in a streamlined mobile environment.

03
Direct Access

Keep HR Defender one tap away on your home screen for regular access to rights, rule-of-law, and accountability content.

How to Install the App

1
Download

Click the Download Android App button above and wait for the APK file to finish downloading.

2
Open File

On your Android device, open the downloaded APK file from the browser, downloads folder, or file manager.

3
Allow Install

If Android asks for permission, allow installation from this source to continue.

4
Install & Open

Tap Install, wait for completion, and then open the HR Defender app from your phone.

Important: Because this version is downloaded directly as an APK, your device may show a security prompt before installation. This is normal for direct Android app installs outside the Play Store.