HomeEditorialsOpinionFeatureReportsArchiveAbout Us
NATIONAL

NID, Call Records and Location Data Still for Sale Online

A Dismislab investigation published on 31 August found NID details, call records and recent location data being sold through Facebook, Telegram, WhatsApp and websites, with researchers successfully purchasing verified information from three sellers. The investigation is the latest in a series of separate data breaches and cases uncovered since 2023, when sensitive information from government systems and NID databases was repeatedly exposed or allegedly sold.

NUTSHELL TODAY DESK
NID, Call Records and Location Data Still for Sale Online
BIONIC READING

In a Nutshell

  • Dismislab’s month-long investigation from 15 June to 15 July 2026 found more than 600 Facebook posts and 10 websites selling personal information, with researchers buying verified NID, call and location data from three sellers.
  • Sellers offered NID and voter details, birth records, call records, mobile locations, SMS lists, IMEI numbers, TINs, passport information and MFS statements, with some records delivered within hours.
  • In 2023, a security flaw in the birth registration system operated by the Office of the Registrar General led to the leak of names, phone numbers, email addresses and NID numbers of millions of citizens. The ICT probe could not determine the scale of the breach or identify those responsible.
  • In 2024, police investigated and arrested people accused of selling genuine NIDs and phone records, while a former EC data centre director was arrested over alleged mirror copies containing information of more than 11 crore citizens.
  • In January 2026, CID found that 365,608 NID records had been accessed in one month in an alleged EC syndicate case, while Dismislab separately found voter lists being sold online in June.
  • Authorities have investigated breaches, suspended or cancelled access for some organisations and introduced laws criminalising unauthorised handling of identifying information, but the latest investigation shows the trade is still operating.

Context

Bangladesh has been dealing with citizen data breaches and unauthorised data sales for years, involving government websites, NID service providers and officials with authorised access.

In 2023, cybersecurity researcher Victor Markopoulos discovered a security flaw in the Office of the Registrar General’s birth registration website that exposed millions of citizens’ names, phone numbers, email addresses, and NID numbers online. An ICT Division probe found weak system architecture and inadequate logging, but could not establish the scale of the exposure or identify anyone responsible.

That year, sensitive NID information also appeared on Telegram, prompting the Election Commission to investigate 171 organisations connected to its NID services. Experts called for continuous monitoring, regular security testing and tighter access controls. By 2024, police found an EC employee’s credentials and OTPs being used to obtain NID information, while former EC data centre director Tareque M Barkatullah was arrested over alleged mirror copies containing data of more than 11 crore citizens.

Why It Matters

This is not a new story; data breaches have occurred for years, with various government websites (including the Office of the Registrar General, Birth and Death Registration, the Election Commission, and others) targeted by hackers. Government systems with high-security measures are easily breached by sellers who put NIDs, call history, and location data up for sale within hours. So, for citizens, the question is not really whether their personal information will be leaked on the open market, but when.

What We Think

Authorities have repeatedly investigated breaches, suspended access, cancelled agreements and detained alleged sellers, yet every year, sensitive information from voting lists to NIDs can be found on the open market without fail.

Given that it poses a national security risk affecting millions of citizens, the relevant authorities must take concrete steps to safeguard the country’s most important systems. Otherwise, we will remain in the investigation and reporting phase, with few changes to protect citizens from falling prey to identity theft and impersonation attempts.

░▒▓█▓▒░