Confirmed data theft, but the scale is still unknown
Pathao has confirmed that attackers obtained some users' names, email addresses and phone numbers during a cybersecurity incident on October 4 that disrupted its operations in Bangladesh and Nepal. The company has not verified a much larger claim that criminals stole 133 gigabytes of information covering 19,063,918 accounts and demanded 400,000 USDT to prevent its release.
Contents
- Confirmed data theft, but the scale is still unknown
- How the incident unfolded
- What the alleged dataset contains
- Employee, merchant and transaction records are also alleged
- The ransom demand remains unconfirmed
- What Pathao says it has done
- Why even contact details can create risks
- What users have been advised to do
- What the investigation still needs to establish
- Key Points
The distinction matters: the theft of some personal information is acknowledged by Pathao, while the alleged exposure of identification records, financial transactions, passwords and location data remains unverified. The company has not disclosed how many people were affected, how attackers entered its systems or how long they had access.
In its October 7 statement on its verified Facebook page, Pathao gave its first public confirmation that personal information had been obtained. The company described the information it understood had reached the attackers:
We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors.
Pathao said it temporarily took critical systems offline after detecting the incident, restored services shortly afterwards and brought in external cybersecurity specialists. Some users could still experience intermittent problems while work to stabilise the platform continued.
The incident reaches beyond a single service. Pathao operates transport and delivery services alongside financial products, including its Pathao Pay digital wallet and Pathao Pay Later service. That range makes establishing which systems and records were affected essential, but the existence of financial products does not itself establish that payment information was stolen.
By October 9, the company was still investigating the larger dataset allegations. It had confirmed disruption in both countries, but had not provided a country breakdown of affected users or records.
How the incident unfolded
The public account spans the initial disruption, the company's acknowledgement and subsequent responses about the alleged dataset. The dates establish when the incident was detected and discussed publicly, not the full duration of the attackers' access.
- October 4: Pathao detected a cybersecurity incident, experienced service disruption and temporarily took critical systems offline as a precaution.
- October 7: Pathao publicly acknowledged that some personal information had been obtained. A screenshot of an alleged criminal forum post also circulated on X, describing a much larger theft and a ransom demand.
- October 9: Further company responses confirmed that operations in Bangladesh and Nepal were affected, while the alleged data volume, record counts and sensitive information categories remained under investigation.
Pathao said services resumed shortly after the shutdown. It has not published the exact length of the interruption or a technical account of the recovery. Restoring access to an app and completing a breach investigation are separate tasks: services can return while investigators continue to establish what information was taken.
What the alleged dataset contains
The criminal claim describes approximately 250 million database rows across 591 tables, with a primary account dataset containing 19,063,918 records. A database row is an individual entry, while a table groups entries of a particular type. Multiple rows can relate to one person, so 250 million rows would not mean 250 million affected users.
The alleged account information includes names, phone numbers, email addresses, password data, GPS information, Facebook identifiers and access tokens. An access token is a digital credential that can allow an application to access an account or service without repeatedly requesting a password.
Reports differ in their description of parts of the claim. One specifies hashed passwords, while another refers simply to passwords. Hashing transforms a password into a stored representation rather than keeping its readable text, although exposure can still create risks depending on how it was protected. Pathao has not confirmed that either form was taken.
The structure is also described differently: some accounts call the 591 units database tables, while another calls them databases or data repositories. Those terms are not interchangeable. Without an authenticated dataset or a technical finding, the exact structure cannot be established.
The alleged identification records comprise 19,059,387 national identity card numbers and 19,046,583 driving licence entries. The claims also include about 5.7 million home addresses and, in some accounts, approximately 19 million user photographs. None of those categories has been verified by Pathao.
Even the precise account count does not establish a count of distinct people. Investigators would need to determine whether records are authentic, current or duplicated before treating the figure as the number of affected users.
Employee, merchant and transaction records are also alleged
The claimed theft extends beyond customer profiles. The alleged dataset includes records concerning 549 employees, with national identity details, salaries, religious affiliations and emergency contact numbers. Other claims describe administrative access records, delivery locations and drivers' journey records.
The financial allegations include 17,943 merchant bank account and routing records, alongside 845,872 direct debit transaction records. Bank routing information identifies the institution or branch involved in a payment. A transaction record documents a payment event, but its presence would not by itself establish that an attacker could move money.
These figures describe different types of records, not a single count that can be added together to establish the number of victims. Employee details, merchant accounts and repeated transactions may overlap with other entries in the alleged dataset.
Pathao's Manager of Partnership and PR, Md. Foyej, said the company had not verified the claims about sensitive categories. In an email response, he stated:
The claims regarding NID, driving licence, location, address or financial data have not been verified at this stage. Any further verified information will be communicated through Pathao’s official channels.
The ransom demand remains unconfirmed
The alleged criminal post demanded 400,000 USDT, described in reports as approximately $400,000. USDT, also known as Tether, is a cryptocurrency designed to track the value of the US dollar. The group reportedly gave Pathao 24 hours to pay and threatened to release information in stages.
The threatened releases reportedly included identification, bank, employee and administrative information. The claim and its deadline could not be independently verified. No confirmed starting time for the deadline, payment decision or subsequent release is established in the accounts.
Foyej, speaking for Pathao, declined to validate the alleged demand:
Pathao does not want to comment on unverified claims regarding ransom demands.
A threat to publish stolen information is a form of data extortion. It does not necessarily mean that attackers encrypted systems or prevented the company from accessing its own files. Pathao has not disclosed evidence of encryption or explained the technical mechanism behind the disruption.
What Pathao says it has done
Pathao's announced response has three main elements: taking critical systems offline, involving external cybersecurity specialists and notifying the relevant authorities. The company said notifications were made to law enforcement or government bodies under applicable rules, but did not identify the agencies or the specific legal provisions.
In its public statement, Pathao described the immediate response and the specialists' role:
Immediate containment measures were taken, and external cybersecurity experts have been engaged to reinforce security controls and help ensure Pathao's systems remain secure and stable.
The company said it was cooperating with authorities as the investigation continued. It apologised to users, drivers, merchants and partners for the incident and disruption, acknowledging its responsibility to protect information entrusted to it.
Foyej also said precautionary measures may have automatically logged some users out. Those users could log in again to use the service. An automatic logout is not, on its own, evidence that a particular person's information was stolen.
Why even contact details can create risks
The confirmed exposure of names, email addresses and phone numbers gives attackers information that can make fraudulent contact appear convincing. A message that addresses someone by name and refers to a service they use may seem more credible than an anonymous request.
Phishing involves posing as a trusted organisation or person to persuade someone to reveal information, follow a malicious link or authorise an action. Pathao warned about this possibility, but did not say that phishing or impersonation attacks linked to the breach had already occurred.
Information technology specialist Suman Ahmed Sabir identified identity theft, banking fraud, phishing, blackmail and social media account compromise as possible risks if the broader allegations prove true. His assessment concerns potential consequences, not confirmed crimes against Pathao users.
The type of information exposed changes the risk. Contact details can support targeted deception; identity documents can support impersonation attempts; location and journey records can reveal private movements. Access tokens may create account security risks, depending on their permissions and whether they remain valid. Pathao has not confirmed exposure of those more sensitive categories.
What users have been advised to do
Pathao's central instruction is to be cautious about unexpected messages, calls and links from anyone claiming to represent the company. It has told users not to share passwords, PINs or one time passwords in response to such communications.
An OTP is a temporary code used to approve a login or transaction. Sharing it can allow someone else to complete the action it protects, even when they do not know the account's regular password.
The company advised users to rely on its official communication channels for verified updates. Security advice discussed in connection with the incident also included avoiding unfamiliar links and enabling two factor authentication on Facebook and other accounts. That adds a second verification step beyond a password.
These precautions address possible misuse of information without assuming that every allegation is true. There is no confirmed count of compromised Facebook accounts, fraudulent transactions or identity theft cases arising from this incident.
What the investigation still needs to establish
Cybersecurity specialist Tanvir Hassan Zoha recommended an independent digital forensic investigation, preservation of relevant servers and access logs, and notification of regulators and law enforcement under applicable law. Digital forensics uses technical evidence to reconstruct what happened, including which systems were accessed and what actions were taken.
Preserving logs matters because they may help establish the entry method, the period of unauthorised access and the records an attacker reached. Pathao has announced the involvement of external specialists, but has not disclosed whether their work is an independent forensic investigation or published its findings.
Sabir also argued that Bangladesh's cybersecurity oversight faces staffing and resource limitations, including within institutions responsible for responding to incidents. He called for a legal framework for compensating customers who suffer losses. Those are his assessments and recommendations, not findings by an authority investigating Pathao.
The immediate unresolved questions are more specific: how many users were affected, which information categories were taken, whether records from both countries were exposed and whether any alleged financial or account credentials are authentic. Pathao has not announced a date for completing the investigation, releasing findings or issuing its next update.
The company's promise to communicate verified information leaves a distinction that users should keep in view. Some personal data theft is confirmed. The claim of a 133 gigabyte dataset containing more than 19 million accounts, extensive identity records and financial information is not.
Key Points
- Pathao confirmed that attackers obtained some names, email addresses and phone numbers during the October 4 incident.
- Operations in Bangladesh and Nepal were disrupted, and some users could face intermittent problems during stabilisation work.
- Claims involving 133 gigabytes, 19,063,918 accounts and approximately 250 million database rows remain unverified.
- Pathao has not confirmed the alleged exposure of passwords, identity records, location data or financial information.
- A reported demand for 400,000 USDT and a 24 hour deadline has not been verified by the company.
- External cybersecurity specialists are involved, relevant authorities have been notified and no investigation completion date has been announced.
- Users have been warned about unsolicited contact and told never to share passwords, PINs or OTPs.






