Cybercriminals Claim to Possess Data of 19 Million Pathao Users; $400,000 Ransom Demanded

Cybercriminals Claim to Possess Data of 19 Million Pathao Users; $400,000 Ransom Demanded

Online Desk
Online Desk

Published: 09:18 9 October 2026

A cybercriminal group has claimed to possess data belonging to approximately 19 million users of the digital service platform Pathao. The group has demanded $400,000 and threatened to release sensitive information if the payment is not made. However, Pathao has not confirmed the leak of data for all 19 million users; the company has only acknowledged unauthorized access to the names, email addresses, and phone numbers of some users.

Citing the cybersecurity platform 'Daily Dark Web,' various media outlets have reported that hackers claim to have stolen data from approximately 19 million Pathao accounts. They have simultaneously demanded a ransom of $400,000. However, it has not been independently verified whether they actually possess this vast amount of data.

Pathao's Statement

Pathao stated that it detected a cybersecurity incident on October 4. Subsequently, as a precautionary measure, certain critical systems were temporarily taken offline. Although services were restored after a while, work to stabilize the systems continued.

According to the company, the perpetrators managed to obtain the names, email addresses, and phone numbers of some users. However, Pathao did not disclose details regarding the number of affected users or how the hackers gained access to the system.

Pathao further stated that external cybersecurity experts have been engaged following the incident, and an investigation is underway to determine the full scope of the breach. The company added that relevant authorities would be informed as necessary.

Hackers' Major Claim

Claims published on the dark web state that the group possesses over 133 gigabytes of Pathao's data. They also claim the data includes approximately 250 million records and over a hundred databases. The hackers further claim that the compromised data includes National ID numbers, driving license details, photographs, home addresses, merchants' banking information, employee data, and administrative access credentials.

However, Pathao has not yet confirmed the specifics of these claims. Consequently, at this stage, it cannot be definitively confirmed that NID, driving license, or banking information has actually been leaked. The only data Pathao has acknowledged as having been accessed consists of names, email addresses, and phone numbers.

Demand for $400,000

Media reports indicate that the hackers have demanded $400,000 USD from Pathao in a dark web post. They have also threatened to release the alleged data in their possession if the payment is not made.

This incident has come to light at a time when Pathao operates as one of Bangladesh's largest digital service platforms. According to the company's own data, it has over 15 million users.

Following the cyberattack, the key questions now are how many users' data has actually been compromised and what specific types of information have fallen into the hackers' hands. To obtain a complete picture, one must await the results of Pathao's investigation and any potential digital forensic analysis.

Advertisement