Skip to content
Pathao data breach: Hackers claim data of 19 million users

Pathao data breach: Hackers claim data of 19 million users

En.Prothomalo • October 9, 2026

A group has claimed to possess the personal data of around 19 million users of digital technology company Pathao.

The group claims the data include mobile phone numbers, email addresses, national identity card (NID) numbers, driving licence details, location data, profiles and addresses. It has demanded USD 400,000 from Pathao in exchange for not disclosing the information.

Cybersecurity platform Daily Dark Web brought the matter to light on social media platform X, formerly Twitter, on Wednesday. It also published a screenshot of the post made on the dark web. However, the claims could not be independently verified.

When asked the matter, Pathao said in a written statement to Prothom Alo shortly after midnight on Thursday night, “We have become aware that miscreants accessed some personal information, including users’ names, email addresses and phone numbers.”

“The incident was contained as soon as it was detected, and external cybersecurity experts have been engaged to secure Pathao’s systems. Once the ongoing investigation establishes the full details of the incident, the relevant authorities will be updated in accordance with the rules,” the statement added.

Pathao said its platform experienced a temporary service disruption on 4 October. After detecting a cybersecurity incident, the company took some of its critical systems offline as a precautionary measure to protect the platform and secure its data.

Services were restored shortly afterwards. However, as work continues to make the systems fully stable, users may experience some minor technical issues temporarily, they added.

Earlier on Wednesday, Pathao said in a statement posted on its verified page that some critical systems had been temporarily shut down as a precaution after a cybersecurity incident was detected on 4 October. This disrupted various services on the platform. Although the services were restored within a short time, work to stabilise the systems fully is ongoing.

The statement said the company had learned that some personal information, including names, email addresses and phone numbers, had fallen into the hands of miscreants during the incident detected on 4 October.

The dark web post claims the group has around 133 gigabytes of Pathao data, comprising approximately 250 million records across 591 databases. It claims that the largest database contains information on 19,063,918 accounts.

The group also claims to possess more than 19 million NID numbers and mobile phone numbers, driving licence information for more than 19 million people, photographs of around 19 million users and approximately 5.7 million addresses.

The group further claims to hold Pathao’s internal and business information. This allegedly includes employee records, administrative access credentials, merchants’ bank account details and bank branch identification codes, financial transaction data, delivery location information and drivers’ trip records.

The post demanded USD 400,000 from Pathao and threatens to release NID, banking, employee and administrative information if the payment is not made.

When asked the matter, cybersecurity expert Tanvir Hassan Zoha told Prothom Alo that the company concerned should immediately arrange an independent digital forensic investigation, preserve all digital evidence, including relevant servers and access logs, and notify the relevant regulators and law enforcement agencies in accordance with applicable laws.

Protecting digital evidence, safeguarding citizens’ personal information and taking evidence-based legal action should be the highest priorities, the cybersecurity expert said.

Extracted Entities

Attack Types (1)

Companies (1)