
Bangladesh ride-hailing and digital services platform Pathao has encountered a major cybersecurity breach, with threat actors claiming on dark web forums to possess approximately 133 gigabytes of compromised user and enterprise data.
The incident was highlighted on Wednesday (October 7, 2026) by cybersecurity monitoring platform Daily Dark Web, which shared screenshots of a dark web posting where hackers demanded $400,000 in ransom. The threat actors claimed to hold over 19 million accounts containing national identity (NID) numbers, driving licenses, phone numbers, email addresses, delivery locations, and employee banking records across 591 databases. In a formal statement released on Thursday (October 8, 2026), Pathao acknowledged that unauthorized actors accessed personal user information including names, email addresses, and phone numbers. The company revealed that upon detecting the breach on October 4, its technical team proactively took core systems offline to prevent further unauthorized access before restoring services. Pathao confirmed it has onboarded external cybersecurity specialists, informed relevant law enforcement and regulatory authorities, and advised users to remain vigilant against phishing, OTP scams, and unauthorized messages.
— Daily Best News Desk • Fearless in the search for truth
Reported by Staff Reporter • Edited by the Daily Best News desk. Send corrections to [email protected].







