Skip to content
Pathao Faces Data Extortion Threat with 19M User Records Allegedly Compromised

Pathao Faces Data Extortion Threat with 19M User Records Allegedly Compromised

First seen 9 Oct 2026, 11:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 12:39 UTC
  • •Threat actor claims to hold 133GB of data from 19 million Pathao users.
  • •Ransom demand of $400,000 with threats of data release if unmet.
  • •Pathao has acknowledged the incident and is working with authorities.

A dark web threat actor has claimed to possess a dataset of approximately 133GB containing personal information of nearly 19 million users of Pathao, a Bangladeshi ride-hailing and fintech platform. The dataset reportedly includes emails, phone numbers, national ID details, and other sensitive information. The attacker has demanded a ransom of $400,000, threatening to release the data if the payment is not made. Pathao has acknowledged the incident and is cooperating with authorities, though the company has not confirmed the breach. The claims made by the threat actor have not been independently verified, and users are advised to be cautious of potential phishing attempts. The situation poses significant risks for identity fraud and SIM-swapping in Bangladesh if the claims are substantiated.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Threat actor posts ransom demand
A dark web user claims to hold Pathao's data and demands $400,000, threatening to release it if not paid.
DailyDarkWeb
2026-10-09
Pathao acknowledges cybersecurity incident
Pathao confirmed a cybersecurity incident and stated it is cooperating with authorities regarding the claims.
Facebook

More articles in this cluster (3)

Following this threat?

Track Pathao in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data is allegedly compromised?
The dataset reportedly includes emails, phone numbers, national ID details, and other personal information of nearly 19 million users.
Has Pathao confirmed the breach?
Pathao has acknowledged a cybersecurity incident but has not confirmed the specifics of the breach.
What should users do to protect themselves?
Users should be vigilant against phishing attempts and change any reused passwords to enhance security.