Hackers claim theft of 19 million Pathao user records, demand $400,000
TLDR
- A hacking group claims to have stolen 133GB of data covering roughly 19 million accounts from Bangladeshi ride-hailing, delivery and fintech platform Pathao, and is demanding $400,000 (in cryptocurrency) not to leak it.23
- Pathao has confirmed malicious actors accessed some users' personal information, including names, email addresses and phone numbers, but has not verified the attackers' claimed scale or identified who is responsible.12
- The alleged dataset reportedly includes national ID numbers, driving licence details, location data, Facebook profile data and home addresses for millions of users, plus internal HR, merchant banking and direct-debit records; none of this has been independently verified.3
- The incident disrupted Pathao's platform on 4 October; services were restored shortly after, though Pathao says some users may still see intermittent issues.23
Cybersecurity monitoring platform Daily Dark Web disclosed on 7 October that a threat actor had posted a listing on an underground forum claiming to hold Pathao's production data and demanding payment.23 According to the listing, the claimed dataset spans roughly 250 million rows across 591 tables, including a user master table of 19,063,918 accounts with emails, phone numbers, names, password hashes, GPS data and Facebook IDs, alongside more than 19 million national ID numbers, over 19 million driving licence entries and roughly 5.7 million home addresses.3 The group also claims to hold HR records for 549 employees and tens of thousands of merchant banking and direct-debit records, and has set a payment deadline with threats to keep releasing data if Pathao does not pay $400,000.123
Pathao, one of Bangladesh's largest ride-hailing, delivery and fintech platforms, has not confirmed the attackers' claimed scale or identified those responsible.12 In a statement posted to its official Facebook page on 7 October, the company said it detected a cybersecurity incident on 4 October that disrupted services, took critical systems offline as a precaution, and has since restored services while continuing stabilisation work.23 "We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors," Pathao said, adding that it has engaged external cybersecurity experts and informed relevant authorities.23 The company did not disclose how many users were affected, how attackers gained access, or whether passwords, payment details or identification documents beyond what it has already confirmed were exposed.2
Dhaka Tribune reports the authenticity and full extent of the attackers' claims cannot be independently verified, and it remains unclear whether the claimed record counts represent unique individuals or duplicate entries tied to the same accounts.2 Pathao has urged users to be alert to phishing attempts and unsolicited messages claiming to represent the company, and to avoid sharing passwords, PINs or one-time codes.3
Why it matters: a $400,000 extortion demand backed by claims of national ID numbers, driving licences and home addresses for a fifth of Bangladesh's population would be one of the country's largest-ever data exposures if confirmed, and the gap between Pathao's narrow public confirmation and the attackers' sweeping claims leaves millions of users unable to judge their own exposure.
Sources
- Pathao data breach: Hackers claim data of 19 million users (Prothom Alo)
- Hackers claim data of 19m Pathao users, demand $400,000 (Dhaka Tribune)
- Hackers claim to have stolen data of nearly 19m Pathao users, demand $400,000 (The Business Standard)