Anyone who wishes to know when you spoke on your mobile phone, with whom, for how long and from which area during the call can, in fact, obtain that information. The price: 1,000 taka. And not just information of a particular day or two. Data covering three months to a year can reach the buyer within hours.
An online market has developed around the buying and selling of ordinary citizens’ personal information. Sellers advertise the “service” on social media, sell data through websites, provide customer support through Telegram channels and collect payments through mobile financial services such as bKash and Nagad.
Beyond call detail records, this market offers citizens’ national identity cards (NID), passport information, lists of SMS to specific numbers, the mobile tower location of a subscriber at a given time, tax identification numbers (TIN), and even mobile financial service account statements. The services are sold at fixed prices through published price lists. All a buyer needs to provide is a mobile number or NID number. Sellers then collect the associated information, often presenting it as an official document or a copy pulled from a government agency’s server.
Dismislab’s investigation found that the online trade of personal information has been ongoing for at least three years. Two mobile operators and one information technology expert were contacted separately about the matter. According to the expert, this kind of information can be obtained in “real time,” or in a fully up-to-date form, only if employees of the relevant government agency are involved, or if a third party has gained access by bypassing the security of data storage systems. In either case, he said, responsibility lies with the relevant institution. One mobile operator said it had raised the issue with the authorities, along with evidence, long ago, but the sales have not stopped.
In a one-month period, from June 15 to July 15, Dismislab searched a single key phrase and found more than 600 Facebook posts advertising the sale of personal information. Following those leads, the investigation identified 10 websites selling citizens’ personal data. Dismislab registered on each website to collect their price lists. Through websites and Facebook posts, Dismislab purchased Call Detail Records (CDR), recent location information and national identity card data for different mobile phone subscribers from three separate sellers, paying for each through bKash.
The sellers provided customer support to a Dismislab reporter through Telegram and WhatsApp. Dismislab verified the personal information obtained from the sellers with the subscribers themselves and found that the data sold, including national identity card information, was accurate.
Call records and a subscriber’s location are highly sensitive personal information. They are typically stored by mobile phone service providers. Under Bangladesh’s laws and regulations, government surveillance agencies and security forces are granted access to such information only in the interest of national security, investigations or maintaining law and order. Yet the same information is now available in the open market, within reach of anyone willing to pay.
NID in 17 minutes, location in 16 minutes, call records in few hours
While investigating the sale of voter lists in June, Dismislab researchers came across a Facebook post. In the comments under that post, one person was advertising the sale of personal information. Following that lead, a search using the term “sign copy” produced 675 Facebook posts. Of those posts, published between June 15 and July 15, 605 offered the sale of personal information. The remaining posts were from interested buyers.
A “sign copy” contains a person’s NID and voter number, date of birth, parents’ names, educational qualifications, marital status, occupation, address, voting area, religion, physical identification marks and signature or thumbprint information. In sellers’ terminology, a “server copy” refers to a PDF bearing the Election Commission’s logo and containing detailed NID information.
Following one such post, a Dismislab reporter found a Telegram link. The link led to a group called “Voter List.” There, an account using the name “Shibat Zubar” posted, “Inbox to get an NID from a number.” When contacted by the reporter posing as a buyer, the account said, if given the mobile number, it could provide the NID of the registered owner of a Subscriber Identity Module (SIM card), or the small chip that identifies a mobile phone subscriber on a network.
With the consent of a subscriber, Dismislab sent his mobile number and an advance payment of 500 taka to Shibat. Within 17 minutes, he sent back a PDF copy of the NID card. Upon verification, the name, photograph, date of birth and all other details matched the SIM’s actual owner. Even the subscriber’s mother’s name, which had been corrected two months earlier, appeared updated in the document. A second verification, conducted the same way using another number, also produced accurate information.
The group’s administrator, operating an account under the name “Help BD,” was advertising the same “service.” In addition to NID “sign copies” and “server copies,” the posts offered birth and death registration records, mobile phone locations, call detail records, SMS lists, IMEI numbers (the identifiers unique to a mobile handset), TIN certificates, police clearance certificates, passport copies and land development tax receipts.
On June 25, Dismislab contacted the administrator while posing as a buyer. When asked what information could be obtained using a mobile number or voter number, the administrator said, “I have a website. I will pull up the server copy and give you the PDF.”
After Dismislab sent 150 taka along with a voter number and date of birth, the administrator sent back a PDF copy of an NID card. Verification showed that the information was accurate. Then, with the consent of another acquaintance, Dismislab paid 250 taka to request the “sign copy” linked to that person’s mobile number. That, too, was received within a short time.
Dismislab then requested three months of call detail records for a Grameenphone number from the same administrator. Within two and a half hours of sending 1,050 taka, Dismislab received the file. The most recent 20 contact numbers, call times and call types in the file were cross-checked against the subscriber’s actual phone call history. Every detail matched.
Call detail records show whom a person spoke with, when and for how long, whether the call was made or received, and whether the phone was connected to a 2G or 4G network at the time. The records also include the IMEI number, which identifies the mobile handset, and the international mobile subscriber identity (IMSI number) which identifies the SIM card. This makes it possible to determine which handset a given SIM was used in.
The file also includes information on the mobile tower or network cell area under which the number was located during a call or SMS. By analyzing such records over an extended period, it becomes possible to estimate a person’s movement patterns.
By analyzing Facebook posts and related WhatsApp and Telegram groups, Dismislab identified 10 active websites selling personal information. Registration on these sites showed that nearly all of them followed the same design and operating procedure. Their dashboards listed prices for several categories of information, including NID, birth registration, TIN certificates, call detail records and mobile location. At least one of the sites were registered in 2025.
Select your service:
Confirm the three-month Call List order for 01XX‑XXXXXX?
bKash Send Money Verification
1. Open bKash and choose “Send Money.”
2. Send the amount to the number below.
Recharge successful
৳2,000 has been added to the account.
Two hours and thirty minutes later
Work History
| # | Order Type | Information | Received | Status | Rate | Time | File |
|---|---|---|---|---|---|---|---|
| 1 | call_list-3 | 01XX‑XXXXXX | success | ৳900 | 2h 30m |
| Date/Time | B‑Party | Dur. | Type | Network | Tower (LAC/CI) |
|---|---|---|---|---|---|
| 2026‑02‑03 09:14 | 018XX‑XXXXXX | 00:02:41 | Out | 4G | 1402 / 45213 |
| 2026‑02‑03 11:52 | 017XX‑XXXXXX | 00:00:38 | In | 4G | 1402 / 45213 |
| 2026‑02‑04 14:07 | 019XX‑XXXXXX | 00:05:12 | Out | 2G | 1188 / 30871 |
| 2026‑02‑05 08:30 | 016XX‑XXXXXX | 00:01:05 | In | 4G | 0942 / 27650 |
| 2026‑02‑05 19:44 | 018XX‑XXXXXX | 00:03:27 | Out | 4G | 0942 / 27650 |
An open-source search identified the owner of one such website. He works as a mobile phone repair technician in Chandpur, a district in southeastern Bangladesh. Through his website, Dismislab requested the location of a Grameenphone number. Within 16 minutes of payment, the site provided the number’s most recent active time, its mobile tower-based location, an address and a Google Maps link.
Big market with sales at different levels
As noted earlier, more than 600 Facebook posts advertising the sale of such information were found in just one month. The scale of the market is also reflected in the number of mobile phone numbers used in the campaign. At least 112 distinct mobile numbers were used for contact in those posts. A single Grameenphone number, 01307****32, appeared in 75 posts. Meanwhile, across 10 websites, Dismislab found 10 distinct mobile financial service numbers used for payment.
Advertisements for the sale of personal information appeared repeatedly in 36 active Facebook groups. Many of the groups had names that directly refer to NID, sign copy or birth registration services. In seven of those groups, such posts appeared at least five times each. Across those seven groups, Dismislab found 114 promotional posts.
These posts, phone numbers and groups were found using one social media platform and a single keyword, “sign copy.” The actual scale could be significantly larger.
At the lowest level of the market, sellers advertise on social media. When a buyer contacts them, these intermediary sellers deposit money into specific websites through bKash, Nagad, Rocket or Upay and place orders for information. They then resell that information at higher prices through WhatsApp, Telegram and social media. As a result, prices listed on websites tend to be lower than the prices charged directly by sellers.
A website owner from Chandpur said he buys mobile subscribers’ call lists for 800 taka and sells them for 900 taka. “If you pay 1,000 taka, I will provide the ID card used to open any given bKash number, and for 4,500 taka, I can also pull the bKash statement,” he said. However, Dismislab could not independently verify whether bKash transaction statements can actually be obtained or not. Following the publication of the report, bKash issued a statement refuting a website owner’s claim that transaction history can be obtained by anyone. bKash’s Head of Corporate Communications Shamsuddin Haider Dalim said, “bKash provides an account statement only to the customer, after verifying their identity through a specific process. In cases requiring investigation, account statements of specific customers may also be provided to designated officials of Bangladesh Bank and the Bangladesh Financial Intelligence Unit (BFIU), and to law enforcement agencies upon court orders and in accordance with legal procedures. Outside of these circumstances, there is no way for anyone to obtain a customer’s account statement from bKash.”
The Chandpur website owner claimed that he obtains the information from another group, and that the group primarily gathers data by bypassing government servers through an application programming interface (API), a system that allows separate software programs to exchange data with each other.
He further claimed, “There is a main police database where you can search using an NID and date of birth to get detailed information. They have built an API out of that. Using ChatGPT to buy a host and build an API, they are selling information for each NID for just 2 to 3 taka.”
Dismislab could not independently verify the technical accuracy of this claim. The identities of the people from whom he said he obtained the information also could not be confirmed.
It is very clear that no one but an insider at the relevant institution can provide real-time information. That means a network is operating here involving people who have access to the relevant database. Or they are getting in through some loophole from outside, one that the data custodian may not even be aware of. Sumon Ahmed Sabir, chief technology officer, Fiber at Home
Everyone knows, yet sales have not stopped
The market for citizens’ personal information has grown in plain sight. Dismislab’s research found posts selling such information dating back to 2023. A YouTube search turned up a video published in March 2025 advertising a similar service. One mobile operator has formally submitted a complaint to the authorities, along with evidence.
Call detail records and basic subscriber location information are held by mobile operators. Asked about the matter, Grameenphone said in a written statement that it places the highest priority on protecting subscriber information and data, and that subscriber information is made available only to authorized individuals in accordance with applicable law, regulatory guidelines and approved standards.
CDR, SIM registration and location-related information is provided only to government agencies authorized under the law, following a set process. There is no possibility of subscriber information going anywhere else. Robi Axiata, written statement
A senior official at one of the country’s mobile operators told Dismislab that more than 10 law enforcement agencies, including the Bangladesh Telecommunication Regulatory Commission (BTRC), the National Telecommunication Monitoring Center (NTMC), and police headquarters, have access to several important systems belonging to the operator. Through this access, they can view and monitor subscribers’ detailed call records and the personal information used in SIM registration.
We conducted our own investigation into who was leaking this information. That investigation found that some information was being leaked using the API of a government law enforcement agency. After we informed the relevant authorities, action was taken against multiple officials at that agency. We have also informed the BTRC about this matter multiple times. A senior mobile-operator official, speaking on condition of anonymity
Col Md Kamrul Hasan Mamun, director of the systems and services division at BTRC, told Dismislab that roughly two months earlier, the Ministry of Home Affairs had formed a committee to work on the issue. The committee reviewed the matter and sent a letter to the ministry. The ministry then forwarded the letter to the BTRC and other relevant institutions with instructions to investigate. Some law enforcement agencies have also been informed of the matter. He said he hoped a decision would be reached within the next month or two.
According to a news report, the NTMC sent a letter to the Ministry of Home Affairs on the matter in April 2024. The letter stated that citizens’ NID cards and call records were being sold in 789 social media groups. The investigation found that the information had been collected using the login credentials and passwords of a police superintendent from the Anti-Terrorism Unit and an assistant police superintendent from RAB-6, a division of the Rapid Action Battalion, or RAB, an elite Bangladeshi paramilitary and law enforcement force. A constable from the cybercrime wing admitted involvement in selling sensitive call records in exchange for money.
Sabir said it is the responsibility of the National Cyber Security Agency (NCSA) to monitor whether institutions handling sensitive information are ensuring proper security. He questioned whether the agency is properly fulfilling that responsibility.
In many cases, an employee may not even think that this is confidential data, that it cannot be leaked and that doing so could violate someone else’s privacy. It raises doubts about whether institutions’ employees even have this basic awareness. Sumon Ahmed Sabir
NCSA’s director general, Md Taibur Rahman, initially agreed to an interview but was later unable to meet. With his consent, questions were sent to him via WhatsApp. He had not responded by the time this report was published.
Subscriber’s NID, call list and location: Where the risks lie
There are significant risks when a national identity card, call detail records or location information falls into someone else’s hands. IT expert Sumon Ahmed Sabir said, “In Bangladesh, the NID functions as a verification tool. If someone has all the information from this NID, they can open a fake account in my name, pretend to be me and commit fraud. It is entirely possible to construct a completely false identity pretending to be me. In the digital age, this is an extremely risky matter for every person.”
“Someone could carry out fake financial transactions or illegal transactions in your name and put you in danger,” he said. “It could also create an opportunity for money to be transferred from your valid account in the future, if additional information is linked to it. All of these issues are interrelated. So the scope of the risk is extremely broad.”
A publication by the Electronic Privacy Information Center (EPIC), a US-based research organization, has shown that data held by data brokers can create distinct kinds of risk for survivors of domestic abuse, immigrants and government officials. In other words, the same type of personal information can cause different kinds of harm depending on who it belongs to.
Bangladesh’s Personal Data Protection Act, 2026, states that personal data collected for a specific purpose cannot be disclosed for any other purpose without that person’s consent, and that an affected individual may file a complaint with the relevant authority if their rights are violated. The law includes provisions for administrative fines for failing to fulfill data protection and security responsibilities. In certain cases, those fines can reach 2.5 million taka.
To seek comment on the sale of personal information, Dismislab contacted the Election Commission, the National Identity Registration Wing, the NTMC and the NCSA.
Mohammad Abdul Momin Sarkar, director of public relations at the Election Commission, said a written application would need to be submitted to the commission to obtain a statement on the matter. Questions sent to AHM Anwar Pasha, director general of the National Identity Registration Wing, went unanswered. An NTMC official declined to comment. A subsequent interview request emailed to the agency’s additional director also went unanswered.
Methodology
For this investigation, Dismislab collected and analyzed 605 social media posts selling personal information over a one-month period. From these posts, active groups, seller accounts, contact numbers, transaction numbers and related websites were identified. To understand how the websites operated, Dismislab registered on them and reviewed publicly available domain-related information.
To test whether the information was actually being supplied, reporters posed as buyers and purchased several NID documents, CDRs and location-related information. In each test, prior consent was obtained from the person concerned, and the information received was cross-checked against their original documents or phone records.
Sensitive information obtained during the investigation was kept secure, and unnecessary personal identifiers were not disclosed in the report. Attempts were also made to obtain comments from relevant sellers, technology experts, mobile operators and government institutions.
This investigation is not a comprehensive account of the entire market. Rather, it presents a picture of the market’s scale and operating methods based on publicly visible promotions and verifiable samples identified during a defined period.
