A dataset claimed to belong to Bangladesh's Directorate of Secondary and Higher Education (DSHE), the body under the Ministry of Education that administers the country's secondary and higher-secondary school system, surfaced on an underground cybercrime forum on or around 23 August 2026. The listing claims more than 390,000 records covering education-sector employees, including National ID numbers, bank account details and salary data. The leak follows closely on a separate claim by a group calling itself Madarax to have stolen and sold the CVs of roughly six million job seekers from Bdjobs, Bangladesh's largest online recruitment platform. Readers should note up front that attribution here is contested: InfoSecBulletin ties the DSHE data to the same Madarax activity cluster that hit Bdjobs, while breach-alert vendor Brinztech attributes the DSHE exfiltration to the BlackLotus ransomware syndicate. No source in this set carries a statement from DSHE, the Ministry of Education, or a Bangladeshi CERT confirming either the intrusion or the record count.
What Happened
The public trail begins with a fragmentary post from the dark web monitoring account Dark Web Intelligence (DailyDarkWeb) on 23 August 2026, naming Bangladesh and DSHE. Undercode News, which covered that initial post, was explicit that the fragment showed no dataset description, no sample records, no screenshots, no named threat actor and no technical evidence, and that calling it a confirmed breach on that basis would be irresponsible. Within hours the same outlet published a second, fuller account describing an alleged database published to an underground forum with more than 390,000 records.
Brinztech, publishing the same day, reported that BlackLotus, a ransomware-as-a-service operation running a double-extortion model, had claimed responsibility on its leak site for exfiltrating "over 390,000 lines" from DSHE database repositories. Brinztech stated plainly that official validation from Bangladeshi authorities or DSHE administration was pending.
InfoSecBulletin frames the DSHE exposure as a sequel to the Bdjobs incident, in which a group named Madarax claimed on the dark web to hold and be selling the personal data of about six million Bangladeshi job seekers. Bdjobs has publicly denied that its platform was breached and asked users not to circulate unverified information. That denial is the closest thing to a first-party statement anywhere in this source set, and it concerns the Bdjobs data, not the DSHE data.
Accounts therefore differ on the central question of who did this. The 390,000 figure is consistent across the sources that cite a number, but the actor label is not, and neither claim has been independently authenticated. It is possible that Madarax and BlackLotus are the same crew under different branding, that one resold the other's data, or that two unrelated actors are advertising overlapping material. On the available evidence, none of those can be ruled in or out.
What Was Taken
Per the threat actor's forum post as reported by Undercode News, the claimed DSHE dataset contains employee names, dates of birth, telephone numbers, email addresses, National ID (NID) numbers, bank account information and salary details, alongside sector-specific identifiers including school codes and MPO codes. MPO (Monthly Pay Order) codes identify institutions receiving government salary subvention, so their presence would map both personnel and the institutions that pay them.
That combination is materially worse than a leaked staff directory. NID numbers in Bangladesh are the master key to bank accounts, SIM registration, land records, pensions, welfare and passports, and as The Daily Star documents, today's smart NID reportedly holds ten-finger impressions, iris scans and 32 categories of personal data across roughly 81 million issued cards. Pairing an NID number with a verified employer, salary figure and bank account produces an impersonation profile that is difficult for a call centre or branch officer to challenge.
The 390,000 count remains an allegation from the seller, not a measured figure. Undercode News said so directly, and Brinztech noted the same. Undercode News describes "lines" of data in the Brinztech framing, which may or may not equal distinct individuals; deduplicated victim counts in leaks of this kind routinely come in lower than the advertised row count.
The parallel Bdjobs claim, per InfoSecBulletin, covers roughly six million CVs and reportedly includes full names, mobile numbers, email addresses, residential information, educational qualifications, employment history and professional skills data. Bdjobs disputes that any breach occurred.
Why It Matters
This is not an isolated event, and defenders should read it as a data point in a documented pattern. Tech Global Institute's "Breached and Unanswered" study logged at least 68 apparent data breach incidents in Bangladesh between January 2023 and May 2026: 36 hitting government organisations and 32 hitting private ones, with exposed material including national identity numbers, biometric records and passport details.
The study's second finding is the operationally important one. Nearly every case in the dataset was discovered by external researchers, news outlets or dark web monitoring services rather than by the breached organisation itself, with only two exceptions across three and a half years. Where a response is traceable at all, it is more often silence or denial than acknowledgment, and published post-mortems are, in the researchers' phrasing, rare to the point of near-absence. The DSHE case is following that script exactly: a monitoring feed found it, the press amplified it, and the institution has said nothing.
Education-sector data in Bangladesh has also been leaking through channels that require no intrusion at all. Agamir Somoy reported on 13 August 2026 that personal data on more than one million SSC and HSC examinees under the Chittagong Board, including roll and registration numbers, GPAs, dates of birth, parents' names and subject-wise scores, had been openly accessible on at least three private websites over four years, two hosted on vercel.app and one on github.io, covering exam years from SSC 2022 through SSC 2026. Official figures cited in that report put 722,399 students through Chittagong Board SSC exams between 2023 and 2026. A significant share of those exposed are minors. Experts quoted by the outlet argue the data could not have surfaced unless the board's official database was compromised; board authorities, per the same report, have dismissed the concerns.
For threat modelling purposes, the takeaway is that an adversary can now plausibly assemble Bangladeshi identity graphs from multiple independent leaks: student records from one source, job-seeker CVs from another, and salaried government employee records with NID and bank details from a third. Cross-referenced, those datasets validate each other and defeat the knowledge-based verification checks that banks, telcos and government portals still rely on.
The Attack Technique
No source in this set describes an initial access vector, a vulnerability, a malware family or a dwell time for the DSHE incident. There is no forensic report, no CERT advisory and no vendor telemetry beyond leak-site monitoring.
What can be said about tradecraft is limited to Brinztech's actor profile: BlackLotus is characterised as a ransomware-as-a-service and extortion-first operation combining encryption routines with large-scale data exfiltration, with a stated focus on public sector bodies and educational directorates holding civil registries, teacher portfolios and student metrics. Whether encryption was deployed against DSHE, or whether this was exfiltration-only extortion, is not stated anywhere in the reporting.
The Madarax activity, by contrast, is described only in terms of the resulting sale listings on dark web forums. No intrusion method has been published for the Bdjobs claim either, and Bdjobs maintains its platform was not breached, which leaves open the alternative that the CV data was aggregated from recruiter-side accounts, third parties or older leaks rather than taken from Bdjobs infrastructure directly. Treat any confident technical narrative about either incident circulating right now as unsourced.
What Organizations Should Do
- Assume NID plus employer plus bank account is now a valid credential set in the wrong hands. Any Bangladeshi bank, telco, fintech or government service that treats NID number, date of birth or salary details as identity proof should move those fields from "verifier" to "public information" in its risk model and require a second, non-leaked factor for account recovery, SIM swap and payroll change requests.
- Hunt for the payroll-diversion fraud pattern specifically. A dataset pairing employees with bank accounts, salary amounts and MPO codes is a ready-made target list for salary redirection scams. Institutions in the MPO system should require out-of-band verification for any bank account change request and alert on clustered change requests across schools sharing a code.
- Close the detection gap that Tech Global Institute documented. If a monitoring feed or a journalist is how you would find out, you have no detection capability. Stand up round-the-clock logging and alerting on database access, egress volume anomalies and administrative authentication for citizen-data repositories, and subscribe to dark web monitoring rather than waiting for it to reach the press.
- Audit for the Chittagong failure mode: data leaving through the front door. Inventory every third-party site, scraper-friendly result portal and unauthenticated API that exposes records from your systems. The Chittagong Board exposure ran through public-hosting platforms for four years. Rate-limit, authenticate and monitor lookup endpoints, and file takedowns against mirrors.
- Prepare a disclosure position before you need one. The dominant institutional response in the Bangladeshi dataset is denial or silence, which measurably degrades the ability of affected citizens to protect themselves. Have a pre-agreed process for verifying a leak claim against internal logs within days, and for notifying affected individuals with concrete guidance.
- Brief staff and citizens on the specific phishing that follows. Leaked education-sector data enables spear-phishing that cites real school codes, real supervisors and real salary figures. Warn affected personnel that convincing, detail-rich approaches are expected, and route all payment and credential requests through verified internal channels.
Independent verification of the DSHE dataset has not been published. Until DSHE, the Ministry of Education or a national CERT speaks, the record count, the data fields and the actor attribution all remain claims made by people selling the data.
Sources: After BDJobs, Directorate of Secondary and Higher Education 390k da... | Bangladesh’s Education Sector Draws Dark Web Attention as Questions... | BlackLotus Ransomware Syndicate Claims Data ... | Bangladesh Education Sector Hit by Alleged Dark Web Breach as 390,0... | BREACHED AND UNANSWERED : A Cartography of Bangladesh's Data Breach... | Bangladesh Data Breaches: A Digital Governance Crisis The Daily Star | Breached and Unanswered: Bangladesh Data Breach Report 2023–2026 T... | Chittagong Education Board: Personal data of 1 Million students leaked