Dark Web Intelligence on X: " BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB ...
Dark Web Intelligence on X: "🇧🇩 BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB DATA EXTORTION, 19M USER RECORDS CLAIMED
A threat actor on an underground forum has posted a public "notice" to Pathao Limited, the Dhaka-based ride-hailing, delivery and fintech super app, claiming to hold its production data and demanding payment.
* ~250 million rows across 591 tables (133 GB)
* A user master table of 19,063,918 accounts with emails, phone numbers, legal names, password hashes, GPS data and IDs/access tokens
* 19,059,387 National ID (NID) numbers and 19,046,583 driving licence entries, plus profile photos and 5.7M addresses
* HR records for 549 employees (NID, salary, religion, emergency contacts), 17,943 merchant bank account/routing records and 845,872 direct-debit records
* A 400,000 USDT ransom demand with a 24-hour deadline, and a threat to keep releasing data
The claim has not been independently verified.
The post lists table names and row counts, but the captured page shows no sample records, so the figures cannot be checked. A Pathao claim from what appears to be the same actor first surfaced a day earlier, and the actor says a local newspaper has already reported a service outage; Pathao has not confirmed either. If genuine, national ID, licence and address data at this scale would create serious identity-fraud and SIM-swap risk in Bangladesh. This is an unverified threat-actor claim, NOT confirmation that Pathao was breached. Users should expect Pathao-themed phishing and account-recovery scams and should change any reused passwords.
#DDW #DarkWeb #Bangladesh #Pathao #DataBreach #Extortion #ThreatIntelligence #CyberSecurity"
🇧🇩 BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB DATA EXTORTION, 19M USER RECORDS CLAIMED
A threat actor on an underground forum has posted a public "notice" to Pathao Limited, the Dhaka-based ride-hailing, delivery and fintech super app, claiming to hold its production data and demanding payment.
* ~250 million rows across 591 tables (133 GB)
* A user master table of 19,063,918 accounts with emails, phone numbers, legal names, password hashes, GPS data and IDs/access tokens
* 19,059,387 National ID (NID) numbers and 19,046,583 driving licence entries, plus profile photos and 5.7M addresses
* HR records for 549 employees (NID, salary, religion, emergency contacts), 17,943 merchant bank account/routing records and 845,872 direct-debit records
* A 400,000 USDT ransom demand with a 24-hour deadline, and a threat to keep releasing data
The claim has not been independently verified.
The post lists table names and row counts, but the captured page shows no sample records, so the figures cannot be checked. A Pathao claim from what appears to be the same actor first surfaced a day earlier, and the actor says a local newspaper has already reported a service outage; Pathao has not confirmed either. If genuine, national ID, licence and address data at this scale would create serious identity-fraud and SIM-swap risk in Bangladesh. This is an unverified threat-actor claim, NOT confirmation that Pathao was breached. Users should expect Pathao-themed phishing and account-recovery scams and should change any reused passwords.
🇧🇩 BANGLADESH: PATHAO ALLEGEDLY HIT WITH 133GB DATA EXTORTION, 19M USER RECORDS CLAIMED
A threat actor on an underground forum has posted a public "notice" to Pathao Limited, the Dhaka-based ride-hailing, delivery and fintech super app, claiming to hold its production data and demanding payment.
* ~250 million rows across 591 tables (133 GB)
* A user master table of 19,063,918 accounts with emails, phone numbers, legal names, password hashes, GPS data and IDs/access tokens
* 19,059,387 National ID (NID) numbers and 19,046,583 driving licence entries, plus profile photos and 5.7M addresses
* HR records for 549 employees (NID, salary, religion, emergency contacts), 17,943 merchant bank account/routing records and 845,872 direct-debit records
* A 400,000 USDT ransom demand with a 24-hour deadline, and a threat to keep releasing data
The claim has not been independently verified.
The post lists table names and row counts, but the captured page shows no sample records, so the figures cannot be checked. A Pathao claim from what appears to be the same actor first surfaced a day earlier, and the actor says a local newspaper has already reported a service outage; Pathao has not confirmed either. If genuine, national ID, licence and address data at this scale would create serious identity-fraud and SIM-swap risk in Bangladesh. This is an unverified threat-actor claim, NOT confirmation that Pathao was breached. Users should expect Pathao-themed phishing and account-recovery scams and should change any reused passwords.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
