SYS::ONLINE
Wasteland.
Briefs1902
Issues23
SinceFeb 2026
LIVE
▣ Breach SHWAPNO-SUPERMARKE 2026-08-13

Shwapno: 410GB Customer Database Stolen in Ransom Extortion

"Shwapno, the retail arm of Bangladesh's ACI group and the country's largest supermarket chain, lost roughly 410 gigabytes of customer data to extortionists who demanded $1.5 million and, when refused, dumped the archive…"

Shwapno, the retail arm of Bangladesh's ACI group and the country's largest supermarket chain, lost roughly 410 gigabytes of customer data to extortionists who demanded $1.5 million and, when refused, dumped the archive on the dark web. Reporting converges on approximately 40 lakh registered customers affected, rendered as "nearly 40 lakh" by Daily Frontline and as "4 million" by Bizz Buzz's summary of the Daily Star investigation. No primary artefact exists: Shwapno has issued no public breach notification, no Bangladesh CERT advisory has been published, and there is no regulator filing. Everything below rests on press reporting, principally the Daily Star investigation syndicated through DataBreaches.net, IANS and others, and on remarks attributed to Shwapno managing director Sabbir Hasan Nasir.

What Happened

The sequence reported by DataBreaches.net, citing Meem Arafat Manab, and matched by Daily Frontline, is that hackers broke into Shwapno's customer database on August 19, 2025. They exfiltrated 410 GB, demanded $1.5 million, and were refused. Shwapno hardened its systems and then said nothing to customers for seven months. In March 2026 the attackers published the stolen data on the dark web. News spread across Bangladeshi social media before Shwapno filed a police report.

Accounts differ on when the intrusion began. Two lower-tier aggregator pieces, windplm and Arctic Publications, both place the breach in December and attribute to Nasir the claim that it went unidentified for roughly three months. Eamar's account splits the difference, describing the compromise as occurring "in August of the previous year." The August 19, 2025 date carries the strongest sourcing, traceable to the Daily Star reporting and reproduced consistently by DataBreaches.net and Daily Frontline; the December claim appears only in the aggregator tier. We treat August 2025 as the likely intrusion date and the December figure as unresolved, possibly a garbled reference to when internal detection occurred.

Eamar reports that Shwapno learned of the compromise not through its own telemetry but from an email sent by the attackers announcing they had the data. If accurate, that is the single most consequential detail in the incident: the victim's detection capability was the extortion note.

Arctic Publications adds that Shwapno is a subsidiary of ACI Limited and that the company engaged forensic experts and law enforcement. That claim sits in the OTHER tier and is unconfirmed elsewhere.

What Was Taken

Every source describing the contents agrees on three categories:

Volume is reported as 410 GB by DataBreaches.net and Daily Frontline. Record counts range from "nearly 40 lakh" (Daily Frontline) to "forty lakh" (DataBreaches.net, IANS) to "4 million" (Bizz Buzz). These are the same figure expressed in different conventions and rounded differently; there is no genuine disagreement on scale.

The purchase-history component is what elevates this above a routine contact-list leak. IANS, summarising the Daily Star report, states the breach mattered precisely because Shwapno "had accumulated years of detailed behavioural data on millions of customers and stored it without adequate protection." A grocery transaction log is a behavioural profile: household size, dietary and religious observance, medication proxies, income band, address inference from store selection, and shopping cadence that reveals travel and absence.

Arctic Publications reports that one customer was able to retrieve a family member's full purchase and transaction history simply by entering their phone number. That is a single OTHER-tier claim and should not be treated as confirmed, but if true it suggests the leaked corpus is trivially queryable by phone number, and possibly that an exposed lookup interface existed independent of the dump.

Why It Matters

The victim never told anyone. Seven months of silence, broken not by disclosure but by the attackers' own publication. Under Bangladesh's Personal Data Protection Act, in force since April 2026, that silence was lawful. Daily Frontline, IANS and Bizz Buzz all report the same structural gap: the Act creates citizen rights and institutional penalties but contains no mandatory breach-notification requirement. Even under the new law, a Bangladeshi company receiving a ransom demand today has no obligation to warn the people whose data is being auctioned.

Enforcement is compromised by design. IANS quotes analysts describing an oversight body that "by its own statute, cannot fully investigate the government that created it," lacking both statutory independence and investigatory reach. The Act also offers no clear mechanism against individuals, as opposed to institutions, trading personal data. DataBreaches.net notes that this gap was made concrete on June 24, 2026, when a Dismislab investigation found the final voter list for Bangladesh's 13th parliamentary election, containing names, voter numbers, parents' names, dates of birth, occupations and permanent addresses, selling openly on Facebook for 30 to 250 taka across 500-plus posts from at least 15 accounts, including paid placements in Facebook's Ad Library. A 250 taka bKash payment bought a Google Drive folder sorted by division and constituency. The Election Commission said it had not authorised the sale, and nobody could identify who was legally accountable.

Retail data is now strategic data in this market. The Daily Star's broader analysis places the Shwapno loss inside a national picture: an NID system holding ten-finger impressions, iris scans and 32 categories of personal data, with roughly 81 million smart cards issued against an electorate of 122 million, and access extended outward to ministries, banks, fintechs and port authorities. IANS reports the Election Commission confirmed earlier in 2026 that five organisations holding legitimate NID API access, including the Directorate General of Health Services, a major bank and the Chittagong Port Authority, had leaked data to third parties. A 4-million-record grocery file with verified phone numbers is a high-quality join key against those leaks. Combined, they enable identity-verified fraud, SIM swap targeting and social engineering at a fidelity neither dataset delivers alone.

Refusing to pay did not contain the damage. Shwapno reportedly declined the $1.5 million, which is defensible policy, but the data was published anyway. Refusal is a payment decision, not an incident response plan, and it does nothing for victims who are never told they are victims.

The Attack Technique

Initial access is not publicly known. No source identifies an exploited vulnerability, a compromised credential, an exposed service or a third-party vector. No named threat actor or extortion brand is attached to the incident in any of the available reporting.

The "ransomware" label should be treated with caution. Bizz Buzz calls it a "ransomware incident" and Eamar frames the demand as "a typical ransomware scenario," but no source describes encryption, operational disruption, or store or supply-chain outage. Every substantive detail available is consistent with data theft and extortion, meaning exfiltrate, threaten publication, demand payment, leak on refusal, rather than with a deployed encryptor. Absent Shwapno confirming otherwise, defenders should model this as an exfiltration-extortion case.

What can be inferred with reasonable confidence:

What Organizations Should Do

  1. Instrument egress, not just perimeter. Set volumetric and behavioural alerting on database exports and outbound transfers from customer-data stores. A 410 GB extraction should have tripped a page. Define a bytes-per-hour baseline for every system holding PII and alert on deviation, including transfers to sanctioned cloud storage.
  2. Cap retention on behavioural data. Years of itemised purchase history multiply breach impact without proportionate business value. Set explicit retention windows for transaction-level records, purge past them, and keep aggregates rather than line items where analytics is the actual requirement.
  3. Break the phone-number join. Phone numbers are the universal identity key across Bangladeshi banking, mobile money and NID-linked services. Tokenise them in analytics and reporting stores, restrict cleartext to the minimum systems, and audit every internal or partner interface that accepts a phone number as a lookup parameter for unauthenticated or over-permissioned access.
  4. Write breach notification into policy, not compliance. Where the law imposes no duty, as under Bangladesh's PDPA, adopt a contractual and policy commitment to notify affected individuals within a fixed window. Seven months of silence converted a security failure into a trust collapse and left millions unable to take defensive steps such as heightened SIM swap and phishing vigilance.
  5. Rehearse the extortion decision before it arrives. Decide in advance who authorises payment refusal, who runs victim communications on refusal, and what the leak-day plan looks like. Refusing to pay is only coherent as a strategy if publication readiness is part of it.
  6. Audit third parties holding your identity keys. The Election Commission's finding that five legitimately authorised NID API consumers leaked data onward is the model risk here. Enumerate every partner with API access to your identity systems, apply rate limiting and query-pattern monitoring per consumer, and require log attestation.
  7. Assume the combined corpus exists. For any organisation serving Bangladeshi consumers, treat name plus phone plus behavioural profile as already available to adversaries. Step up authentication for high-risk actions rather than relying on knowledge-based verification that this data now defeats.

Sources: Shwapno Data Breach: What You Need to Know & How to Protect Yoursel... | Why Bangladesh’s new data protection law may fail to protect your d... | Data Breaches Expose Millions, Reveal Gaps in Bangladesh’s Privacy... | Bangladesh Data Breaches: A Digital Governance Crisis | Bangladesh’s data protection law lacks power to protect citizen dat... | Bangladesh Data Protection Law Faces Scrutiny Over Weak Privacy Saf... | Shwapno Data Breach: 40 Lakh Customers' Details Exposed! Hackers De... | Shwapno Data Breach: Hackers Demand $1.5M! What You Need to Know (2...