The breaches were found by almost everyone except the institutions that suffered them
Between January 2023 and May 2026, at least 68 data breach incidents affecting both government institutions and the private sector appear to have occurred in Bangladesh. Drawing from cybersecurity advisories, dark-web monitoring services, threat-intelligence feeds, and mainstream newspapers, our findings revealed that of these data breaches, 36 involved government organisations and 32 involved private ones. The data exposed across these incidents includes, but is not limited to, national identity numbers, biometric records, passport details, and other personally identifiable information.
A second finding runs throughout almost every incident in the dataset: the failure of institutions to recognise warning signs of a data breach — institutional blindness. Almost all documented cases involved breaches identified by external security researchers, news outlets, or dark-web monitoring services rather than by the affected organisations themselves; the two rare exceptions were the Bangladesh Election Commission’s detection of leaks within its own verification ecosystem and one police investigation into an alleged breach. Where a response can be traced at all, it is far more often silence or denial than an acknowledgment, and a published post-mortem or forensic analysis is rare to the point of near-absence. These organisations also do not run bug bounty programs that reward the good actors who tend to surface these vulnerabilities and report them via the institutions’ official channels.