Cyber & AI intelligence
Wasteland.
Briefs indexed3095
Issues31
Published Mondays07:30 CT
▣ Breach PATHAO-DATA-BREACH 2026-10-09

Pathao: Confirmed Cyberattack and Unverified 19M-User Extortion Claim

"Pathao, one of Bangladesh's largest ride-hailing, delivery and fintech platforms, has confirmed that attackers took users' names, email addresses and phone numbers during a cybersecurity incident it detected on 4…"

Pathao, one of Bangladesh's largest ride-hailing, delivery and fintech platforms, has confirmed that attackers took users' names, email addresses and phone numbers during a cybersecurity incident it detected on 4 October 2026. The company has not said how many people are affected. A threat actor says it holds data on nearly 19 million Pathao users and wants $400,000, according to The Business Standard and AliasFleet, based on a dark web listing. That figure and the ransom demand come only from the attackers' own claims and have not been verified. All eight sources behind this brief are secondary reports or monitoring feeds. None is a primary disclosure. Pathao's own statement is known only through how those outlets quote it.

What Happened

4 October (Sunday): Pathao says it detected a cybersecurity incident that disrupted services across its platform. It says it immediately took critical systems offline as a precaution (TBS, AliasFleet, Techpana).

5 October (Monday): In Kathmandu, Nepal-based users and riders still could not use the app, according to Nepal on the Web. That outlet reported social media rumours of a hack and of a ransom demand. It also quoted unnamed people familiar with the situation who said the outage might be a technical glitch rather than an attack. Pathao's later statement contradicts that explanation.

6 October, 16:07 UTC: The Kalir Pulse monitoring feed flagged a threat actor's claim of a breach exposing about 19 million users' identity and contact data.

7 October, 05:07 UTC: Kalir recorded a separate extortion "notice" that a threat actor had posted, addressed to Pathao Limited.

7 October: Pathao published a statement on its official Facebook page. It confirmed the incident, said services had been restored with some intermittent problems continuing, and said it had brought in outside cybersecurity experts and informed the relevant authorities. Techpana reported the same statement for Pathao's Nepal operation.

8–9 October: The Business Standard reported both the company's confirmation and the attackers' claim of 19 million records with a $400,000 demand.

Where accounts differ on the ransom: English-language coverage cites $400,000 (TBS, AliasFleet). Nepali social media claims cited by Nepal on the Web put the demand at Rs 70 million to Rs 80 million. Pathao Nepal has not confirmed those figures. Neither number is verified. They may be the same demand converted into another currency, separate demands, or rumours that drifted as they spread.

What Was Taken

Confirmed by Pathao, as reported by TBS and AliasFleet: names, email addresses and phone numbers. In Nepali, Techpana describes the exposure more cautiously, as a risk that unauthorised people may have reached "partial" customer information.

Claimed but not verified: - Number of people affected: Pathao has given no figure. The attackers claim nearly 19 million users (TBS, Kalir). Kalir describes them as Bangladeshi users. No source says whether Nepal users are included. - Other data: Kalir's summary refers to "identity and contact data". Pathao has not said whether passwords, payment details, ID documents or trip history were affected (TBS).

Also unknown: how long the attackers were inside, whether any data has been leaked publicly, and whether any of it is being sold.

Why It Matters

The Attack Technique

Not disclosed. Pathao has not said how the attackers got in or how long they had access (TBS, AliasFleet). No source names a threat actor group, a malware family or a vulnerability. Pathao's Couriertech unit recently posted a LinkedIn job ad that publicly describes parts of its internal stack, including BigQuery, Metabase, Retool and Appsmith admin panels, n8n and Make workflows, webhooks and LLM agent services. Nothing connects that stack to this incident, and it should not be read as an indicator. It is mentioned only as an example of the kind of information that job ads routinely reveal to attackers.

What Organizations Should Do

  1. Prepare for impersonation now. Treat the confirmed fields as already circulating. Brief call centres, fraud teams and payment partners to expect phishing and vishing that uses the Pathao brand. Tighten OTP and SIM-swap checks for phone numbers linked to Pathao accounts.
  2. Monitor for leaks. Watch the extortion listing and paste and leak sites for a sample or full release. A sample would confirm the scope and show which fields beyond the three confirmed ones were taken.
  3. Lock down high-value internal tools. Put admin panels, low-code tools and workflow automation platforms behind SSO with phishing-resistant MFA. Rotate the API keys and webhook secrets they hold, and log queries that pull data in bulk from analytics warehouses.
  4. Check what your company reveals publicly. Review job ads and engineering posts for detail about your internal tooling, and make sure every tool they name is in your asset inventory and covered by monitoring.
  5. Communicate through one verified channel. As Pathao did, tell users that official information will come only from known channels, and say clearly that staff will never ask for passwords, PINs or OTPs.
  6. Rehearse taking systems offline. Pathao's quick shutdown limited the damage but caused outages in several countries. Practise segmented isolation so you can contain an attack without taking your whole platform down.

Sources: Hackers claim to have stolen data of nearly 19m Pathao users, deman... | Pathao Confirms Cyberattack Exposed Names, Emails, Phones | 𝐑𝐞𝐚𝐝𝐲 𝐭𝐨 𝐂𝐡𝐚𝐥𝐥𝐞𝐧𝐠𝐞, 𝐂𝐫𝐞𝐚𝐭𝐞 & 𝐂𝐡𝐚𝐧𝐠𝐞 𝐭𝐡𝐞 𝐂𝐨𝐮𝐫𝐢𝐞𝐫 𝐥𝐚𝐧𝐝𝐬𝐜𝐚𝐩𝐞? Pathao | Cyberattack exposed users' names, emails and phone numbers, says Pa... | When Pathao went blank: A Monday without a familiar ride - N O W | साइबर आक्रमणको जोखिमपछि पठाओका केही सिस्टम बन्द, भन्यो- ‘ओटीपी र पा... | Pathao data breach exposes 19M Bangladeshi users' personal data · K... | Extortion notice to Bangladeshi firm Pathao Limited · Kalir Brief ·...