Facebook Pathao Faces Data Extortion Threat with 19M User Records Allegedly Compromised
Article Content
- •Threat actor claims to hold 133GB of data from 19 million Pathao users.
- •Ransom demand of $400,000 with threats of data release if unmet.
- •Pathao has acknowledged the incident and is working with authorities.
A dark web threat actor has claimed to possess a dataset of approximately 133GB containing personal information of nearly 19 million users of Pathao, a Bangladeshi ride-hailing and fintech platform. The dataset reportedly includes emails, phone numbers, national ID details, and other sensitive information. The attacker has demanded a ransom of $400,000, threatening to release the data if the payment is not made. Pathao has acknowledged the incident and is cooperating with authorities, though the company has not confirmed the breach. The claims made by the threat actor have not been independently verified, and users are advised to be cautious of potential phishing attempts. The situation poses significant risks for identity fraud and SIM-swapping in Bangladesh if the claims are substantiated.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Pathao in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data is allegedly compromised?
Has Pathao confirmed the breach?
What should users do to protect themselves?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…