A cybercriminal group has claimed to have stolen 133GB of sensitive data belonging to 19 million customers from the servers of Pathao, a Bangladeshi technology company offering ride-sharing, delivery and financial services.
Pathao, in a statement on Wednesday (7 October), did not confirm the alleged scale of the breach or identify those responsible. However, the company acknowledged that some users’ personal information had fallen into the hands of “malicious actors”.
The hackers claim the stolen data includes mobile phone numbers, email addresses, national identity card (NID) numbers, driving licence details, location data, Facebook profiles and home addresses.
They have reportedly demanded cryptocurrency worth $400,000 from Pathao in exchange for the data.
The cybersecurity platform Dark Web Intelligence reported the alleged breach on X on Wednesday. It also shared a screenshot of the post published on the dark web.
The claims, however, could not be independently verified.
What data does the group claim to possess?
According to the dark web post, the alleged database contains around 250 million rows of data stored across 591 tables.
The person behind the post claims to have obtained a primary user database containing records of 19,063,918 accounts.
The database allegedly includes email addresses, phone numbers, names, hashed passwords, GPS data, Facebook IDs and access tokens.
The post also claims to contain 19,059,387 NID card numbers and 19,046,583 driving licence records. It further alleges that the database includes around 5.7 million home addresses.
Beyond customer information, the hackers claim to have obtained internal records of 549 Pathao employees, including NID details, salaries, religious affiliations and emergency contact numbers.
The alleged haul also includes 17,943 merchant bank account and routing records, as well as information on 845,872 direct-debit financial transactions.
The group has demanded 400,000 USDT, a cryptocurrency known as Tether, pegged to the US dollar, as ransom for the data.
It reportedly gave Pathao just 24 hours to pay, threatening to release the confidential information online in stages if the payment was not made.
The claimed volume and nature of the stolen data have yet to be independently verified.
Pathao acknowledges data breach
In its statement, Pathao outlined its response to the incident but did not confirm the alleged theft of 133GB of data, the reported records of nearly 19 million accounts or the $400,000 ransom demand.
The company said its platform experienced service disruptions on 4 October.
After detecting a cybersecurity incident, it temporarily took some critical systems offline as a precaution to protect the platform’s security. Services were restored shortly afterwards, according to Pathao.
“We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors,” Pathao said, adding, “Relevant authorities have been informed, and Pathao is cooperating closely with them as the investigation and response continue.”
Pathao urged customers to remain vigilant in light of the breach. It advised users to be cautious of unsolicited messages, phone calls and links from anyone claiming to represent the company.
Users were also warned never to share their passwords, PINs or one-time passwords (OTPs) with anyone.
The company apologised to users, drivers, merchants and partners for the disruption to its services.
