Pathao, one of Bangladesh’s largest ride-hailing and delivery platforms, has said malicious actors obtained some users’ personal information following a cybersecurity incident that disrupted services across its platform on 4 October.
In a statement posted on its official Facebook page on 7 October, Pathao said it took critical systems offline immediately after detecting the incident as a precaution to protect the integrity and security of its systems.
The company said its services were restored shortly afterwards, although some users may continue to experience intermittent problems as stabilisation work continues.
“We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors,” Pathao added.
The company did not disclose how many users were affected or explain how the attackers gained access to its systems.
Pathao also said it took immediate containment measures after detecting the incident and engaged external cybersecurity experts to strengthen its security controls and help keep its systems secure and stable.
It did not specify whether any other categories of personal information were obtained. The company has also not publicly said whether passwords, payment information, identification documents or other sensitive data were affected.
Pathao further said relevant authorities had been informed and that it was cooperating with them as the investigation and response continued.
The company has not disclosed the number of affected users, the duration of the incident or the method through which the malicious actors obtained the information.
Pathao warns users
Pathao warned users to remain cautious of unsolicited messages, calls or links claiming to represent the company following the incident.
“We urge users to remain cautious of unsolicited messages, calls or links claiming to represent Pathao, and should never share passwords, PINs or OTPs in response to such communications,” it said.
The company did not say that any phishing or impersonation attempts had already taken place. However, it urged users to be alert to communications that may falsely claim to be from Pathao.
The company advised users to rely on its official channels for verified updates and guidance regarding the incident.
Pathao has not publicly disclosed the total number of users whose information may have been obtained or whether the incident involved unauthorised access to any other systems or databases.
It also has not publicly confirmed claims circulating online about a substantially larger dataset allegedly being taken from its systems.
Pathao said it would continue to share updates as further information was verified.
The company apologised to users, drivers, merchants and partners for the incident and disruption, saying it recognised the trust placed in it and its responsibility to protect users’ information.
