Data For Sale

Almost Everything About You, for Sale

How protected data became cheap, searchable and saleable
An NID in 17 minutes. A location in 16. A call history in hours. Bangladesh’s personal data is for sale — and delivery is fast.
NID card name · DOB · ID number
Live location coordinates · cell ID
Call records numbers · duration · tower
Sign copy address · voter number

Anyone who wishes to know when you spoke on your mobile phone, with whom, for how long and from which area during the call can, in fact, obtain that information. The price: 1,000 taka. And not just information of a particular day or two. Data covering three months to a year can reach the buyer within hours.

An online market has developed around the buying and selling of ordinary citizens’ personal information. Sellers advertise the “service” on social media, sell data through websites, provide customer support through Telegram channels and collect payments through mobile financial services such as bKash and Nagad.

Beyond call detail records, this market offers citizens’ national identity cards (NID), passport information, lists of SMS to specific numbers, the mobile tower location of a subscriber at a given time, tax identification numbers (TIN), and even mobile financial service account statements. The services are sold at fixed prices through published price lists. All a buyer needs to provide is a mobile number or NID number. Sellers then collect the associated information, often presenting it as an official document or a copy pulled from a government agency’s server.

Dismislab’s investigation found that the online trade of personal information has been ongoing for at least three years. Two mobile operators and one information technology expert were contacted separately about the matter. According to the expert, this kind of information can be obtained in “real time,” or in a fully up-to-date form, only if employees of the relevant government agency are involved, or if a third party has gained access by bypassing the security of data storage systems. In either case, he said, responsibility lies with the relevant institution. One mobile operator said it had raised the issue with the authorities, along with evidence, long ago, but the sales have not stopped.

In a one-month period, from June 15 to July 15, Dismislab searched a single key phrase and found more than 600 Facebook posts advertising the sale of personal information. Following those leads, the investigation identified 10 websites selling citizens’ personal data. Dismislab registered on each website to collect their price lists. Through websites and Facebook posts, Dismislab purchased Call Detail Records (CDR), recent location information and national identity card data for different mobile phone subscribers from three separate sellers, paying for each through bKash.

600+
Facebook posts advertising personal data for sale, found in one month
10
Active websites identified selling citizens’ data
3
Separate sellers Dismislab bought real data from, paid via bKash
5
Real documents and records obtained as evidence — NID, sign copy, server copy, location and call records

The sellers provided customer support to a Dismislab reporter through Telegram and WhatsApp. Dismislab verified the personal information obtained from the sellers with the subscribers themselves and found that the data sold, including national identity card information, was accurate.

Call records and a subscriber’s location are highly sensitive personal information. They are typically stored by mobile phone service providers. Under Bangladesh’s laws and regulations, government surveillance agencies and security forces are granted access to such information only in the interest of national security, investigations or maintaining law and order. Yet the same information is now available in the open market, within reach of anyone willing to pay.

NID in 17 minutes, location in 16 minutes, call records in few hours

While investigating the sale of voter lists in June, Dismislab researchers came across a Facebook post. In the comments under that post, one person was advertising the sale of personal information. Following that lead, a search using the term “sign copy” produced 675 Facebook posts. Of those posts, published between June 15 and July 15, 605 offered the sale of personal information. The remaining posts were from interested buyers.

A “sign copy” contains a person’s NID and voter number, date of birth, parents’ names, educational qualifications, marital status, occupation, address, voting area, religion, physical identification marks and signature or thumbprint information. In sellers’ terminology, a “server copy” refers to a PDF bearing the Election Commission’s logo and containing detailed NID information.

Following one such post, a Dismislab reporter found a Telegram link. The link led to a group called “Voter List.” There, an account using the name “Shibat Zubar” posted, “Inbox to get an NID from a number.” When contacted by the reporter posing as a buyer, the account said, if given the mobile number, it could provide the NID of the registered owner of a Subscriber Identity Module (SIM card), or the small chip that identifies a mobile phone subscriber on a network.

Real conversation, restaged. Every line below is transcribed from Dismislab’s actual conversations with data sellers on Telegram, combined here into one scrolling thread to show the shape of a deal from ask to delivery. The seller’s payment details are masked. Scroll to follow the conversation.
DS
Data seller

With the consent of a subscriber, Dismislab sent his mobile number and an advance payment of 500 taka to Shibat. Within 17 minutes, he sent back a PDF copy of the NID card. Upon verification, the name, photograph, date of birth and all other details matched the SIM’s actual owner. Even the subscriber’s mother’s name, which had been corrected two months earlier, appeared updated in the document. A second verification, conducted the same way using another number, also produced accurate information.

The group’s administrator, operating an account under the name “Help BD,” was advertising the same “service.” In addition to NID “sign copies” and “server copies,” the posts offered birth and death registration records, mobile phone locations, call detail records, SMS lists, IMEI numbers (the identifiers unique to a mobile handset), TIN certificates, police clearance certificates, passport copies and land development tax receipts.

On June 25, Dismislab contacted the administrator while posing as a buyer. When asked what information could be obtained using a mobile number or voter number, the administrator said, “I have a website. I will pull up the server copy and give you the PDF.”

After Dismislab sent 150 taka along with a voter number and date of birth, the administrator sent back a PDF copy of an NID card. Verification showed that the information was accurate. Then, with the consent of another acquaintance, Dismislab paid 250 taka to request the “sign copy” linked to that person’s mobile number. That, too, was received within a short time.

Dismislab then requested three months of call detail records for a Grameenphone number from the same administrator. Within two and a half hours of sending 1,050 taka, Dismislab received the file. The most recent 20 contact numbers, call times and call types in the file were cross-checked against the subscriber’s actual phone call history. Every detail matched.

The paper trail — what came back
Five transactions, five results, reconstructed below as AI-generated demos with fictional data — the layout and fields in each match exactly what sellers delivered.
OBTAINED
17
min
৳500
via “Shibat Zubar”
AI-generated demo national ID card, built to resemble the actual card Dismislab obtained from the seller, using fictional placeholder data for the name, photo, date of birth, ID number, parents' names and address
An AI-generated demo card, built to resemble the actual NID Dismislab obtained from the seller
OBTAINED
20
min
৳250
“sign copy,” via “Help BD”
AI-generated demo backend record, built to resemble the actual sign-copy document Dismislab obtained from the seller, using fictional placeholder data
An AI-generated demo document, built to resemble the actual sign copy document Dismislab obtained from the seller
CASE FILE 03
OBTAINED
20
min
৳150
“server copy,” via “Help BD”
AI-generated demo NIDW search result page, built to resemble the actual server copy document Dismislab obtained from the seller, using fictional placeholder data
An AI-generated demo document, built to resemble the actual server copy document Dismislab obtained from the seller
CASE FILE 04
OBTAINED
16
min
৳1,500
via a Chandpur reseller site
AI-generated demo location lookup result, built to resemble the actual result Dismislab obtained from the seller, using fictional placeholder data for the MSISDN, coordinates and address
An AI-generated demo result, built to resemble the actual location lookup Dismislab obtained from the seller
CASE FILE 05
OBTAINED
2.5
hrs
৳1,050
call records, via “Help BD”
AI-generated demo call detail records export, built to resemble the actual call list Dismislab obtained from the seller, using fictional placeholder data for the caller and recipient numbers, IMEI, IMSI and address fields
An AI-generated demo call list, built to resemble the actual call detail records Dismislab obtained from the seller
All five results were cross-checked against the subscribers’ actual records and found accurate, down to a recently corrected detail in one case. The genuine three-month CDR file included start time, both numbers, duration, call type, network, tower and cell IDs, IMEI, IMSI and address, spanning several districts as the subscriber travelled — the card above reconstructs that layout using fictional demo data.

Call detail records show whom a person spoke with, when and for how long, whether the call was made or received, and whether the phone was connected to a 2G or 4G network at the time. The records also include the IMEI number, which identifies the mobile handset, and the international mobile subscriber identity (IMSI number) which identifies the SIM card. This makes it possible to determine which handset a given SIM was used in.

The file also includes information on the mobile tower or network cell area under which the number was located during a call or SMS. By analyzing such records over an extended period, it becomes possible to estimate a person’s movement patterns.

By analyzing Facebook posts and related WhatsApp and Telegram groups, Dismislab identified 10 active websites selling personal information. Registration on these sites showed that nearly all of them followed the same design and operating procedure. Their dashboards listed prices for several categories of information, including NID, birth registration, TIN certificates, call detail records and mobile location. At least one of the sites were registered in 2025.

Registering as a buyer — the ordering flow
Dismislab registered on one of the ten sites to see the process firsthand. The screens below are recreated to show how the ordering flow works — not screenshots of the real site.
Recreated — Not the Real Site
৳0DS
Accounts with a ৳0 balance may be removed. Please recharge promptly.
Select your service:
Server Copy Official (৳50)
TIN Certificate (৳50)
NID from Mobile Number (৳250)
Call List – 3 Months (৳900)
Call List – 6 Months (৳1,800)
Nagad Statement (৳7,000)
Live Location (৳1,500)
Certificate Delivery (৳5,000)
New Birth Registration (৳2,100)
NID by Name and Address (৳650)
bKash Information Service (৳7,500)
Case Check (৳1,000)
Sign Copy (৳250)
Smart Card PDF Form (৳300)
NID Server Copy (৳200)
New TIN (৳500)
Voter Number → NID (৳150)
Passport First Page Print (৳2,500)
bKash Send Money Verification

1. Open bKash and choose “Send Money.”
2. Send the amount to the number below.

016XX‑XXXXXXCopy
Demo Account
2,000
01XX‑XXXXXX
DEMO1234X
Recharge successful

৳2,000 has been added to the account.

Number01XX‑XXXXXXTransactionDEMO1234XNew balance৳2,000
2:30

Two hours and thirty minutes later

Work History
#Order TypeInformationReceivedStatusRateTimeFile
1call_list-301XX‑XXXXXXsuccess৳9002h 30m
call_list_3mo.xlsxDownloaded · demo data
Date/TimeB‑PartyDur.TypeNetworkTower (LAC/CI)
2026‑02‑03 09:14018XX‑XXXXXX00:02:41Out4G1402 / 45213
2026‑02‑03 11:52017XX‑XXXXXX00:00:38In4G1402 / 45213
2026‑02‑04 14:07019XX‑XXXXXX00:05:12Out2G1188 / 30871
2026‑02‑05 08:30016XX‑XXXXXX00:01:05In4G0942 / 27650
2026‑02‑05 19:44018XX‑XXXXXX00:03:27Out4G0942 / 27650

An open-source search identified the owner of one such website. He works as a mobile phone repair technician in Chandpur, a district in southeastern Bangladesh. Through his website, Dismislab requested the location of a Grameenphone number. Within 16 minutes of payment, the site provided the number’s most recent active time, its mobile tower-based location, an address and a Google Maps link.

Big market with sales at different levels

As noted earlier, more than 600 Facebook posts advertising the sale of such information were found in just one month. The scale of the market is also reflected in the number of mobile phone numbers used in the campaign. At least 112 distinct mobile numbers were used for contact in those posts. A single Grameenphone number, 01307****32, appeared in 75 posts. Meanwhile, across 10 websites, Dismislab found 10 distinct mobile financial service numbers used for payment.

Advertisements for the sale of personal information appeared repeatedly in 36 active Facebook groups. Many of the groups had names that directly refer to NID, sign copy or birth registration services. In seven of those groups, such posts appeared at least five times each. Across those seven groups, Dismislab found 114 promotional posts.

The accounts and groups behind the posts
Facebook accounts with the most posts advertising sign‑copy / server‑copy sales, June 16 – July 15
These posts were made from at least 149 profiles across 133 Facebook groups. Of those groups, nine are no longer active. A total of 117 posts were made from accounts that concealed their identity. The chart above lists the 10 accounts that posted the most.
The five most active of the seven Facebook groups where sign‑copy / server‑copy posts appeared at least five times each
Group names translated from Bengali. Several groups are named directly for the services on sale — “Sign Copy / Server Copy,” “Birth Registration Help Center” — making them easy for buyers to find with a single search.

These posts, phone numbers and groups were found using one social media platform and a single keyword, “sign copy.” The actual scale could be significantly larger.

At the lowest level of the market, sellers advertise on social media. When a buyer contacts them, these intermediary sellers deposit money into specific websites through bKash, Nagad, Rocket or Upay and place orders for information. They then resell that information at higher prices through WhatsApp, Telegram and social media. As a result, prices listed on websites tend to be lower than the prices charged directly by sellers.

A website owner from Chandpur said he buys mobile subscribers’ call lists for 800 taka and sells them for 900 taka. “If you pay 1,000 taka, I will provide the ID card used to open any given bKash number, and for 4,500 taka, I can also pull the bKash statement,” he said. However, Dismislab could not independently verify whether bKash transaction statements can actually be obtained or not. Following the publication of the report, bKash issued a statement refuting a website owner’s claim that transaction history can be obtained by anyone. bKash’s Head of Corporate Communications Shamsuddin Haider Dalim said, “bKash provides an account statement only to the customer, after verifying their identity through a specific process. In cases requiring investigation, account statements of specific customers may also be provided to designated officials of Bangladesh Bank and the Bangladesh Financial Intelligence Unit (BFIU), and to law enforcement agencies upon court orders and in accordance with legal procedures. Outside of these circumstances, there is no way for anyone to obtain a customer’s account statement from bKash.”

The price list
Published prices collected by registering on 10 data‑selling websites. Orange markers show what Dismislab actually paid, or was quoted, for that category during this investigation.
Published price range Price actually paid by Dismislab
Prices in Bangladeshi taka (৳). “Server copy” and “sign copy” refer to two different NID document formats sold by these sites (see previous section).

The Chandpur website owner claimed that he obtains the information from another group, and that the group primarily gathers data by bypassing government servers through an application programming interface (API), a system that allows separate software programs to exchange data with each other.

He further claimed, “There is a main police database where you can search using an NID and date of birth to get detailed information. They have built an API out of that. Using ChatGPT to buy a host and build an API, they are selling information for each NID for just 2 to 3 taka.”

Dismislab could not independently verify the technical accuracy of this claim. The identities of the people from whom he said he obtained the information also could not be confirmed.

It is very clear that no one but an insider at the relevant institution can provide real-time information. That means a network is operating here involving people who have access to the relevant database. Or they are getting in through some loophole from outside, one that the data custodian may not even be aware of. Sumon Ahmed Sabir, chief technology officer, Fiber at Home

Everyone knows, yet sales have not stopped

The market for citizens’ personal information has grown in plain sight. Dismislab’s research found posts selling such information dating back to 2023. A YouTube search turned up a video published in March 2025 advertising a similar service. One mobile operator has formally submitted a complaint to the authorities, along with evidence.

A timeline of warnings
March 2023
Earliest Facebook posts advertising sale of citizens’ personal data found by Dismislab in this investigation.
April 2024
NTMC sends a letter to the Ministry of Home Affairs stating that citizens’ NID cards and call records were being sold in 789 social media groups — traced in part to leaked police login credentials.
2025
At least one of the 10 data-selling websites identified by Dismislab is registered. In March, a YouTube video advertising a similar data-selling service is published and remains publicly viewable.
June 2026
The Ministry of Home Affairs forms a committee to work on the issue, roughly two months before Dismislab’s report is published.
June–July 2026
Dismislab identifies 605 posts, 10 active websites, and buys real NID, location and call data from three sellers.

Call detail records and basic subscriber location information are held by mobile operators. Asked about the matter, Grameenphone said in a written statement that it places the highest priority on protecting subscriber information and data, and that subscriber information is made available only to authorized individuals in accordance with applicable law, regulatory guidelines and approved standards.

CDR, SIM registration and location-related information is provided only to government agencies authorized under the law, following a set process. There is no possibility of subscriber information going anywhere else. Robi Axiata, written statement

A senior official at one of the country’s mobile operators told Dismislab that more than 10 law enforcement agencies, including the Bangladesh Telecommunication Regulatory Commission (BTRC), the National Telecommunication Monitoring Center (NTMC), and police headquarters, have access to several important systems belonging to the operator. Through this access, they can view and monitor subscribers’ detailed call records and the personal information used in SIM registration.

We conducted our own investigation into who was leaking this information. That investigation found that some information was being leaked using the API of a government law enforcement agency. After we informed the relevant authorities, action was taken against multiple officials at that agency. We have also informed the BTRC about this matter multiple times. A senior mobile-operator official, speaking on condition of anonymity

Col Md Kamrul Hasan Mamun, director of the systems and services division at BTRC, told Dismislab that roughly two months earlier, the Ministry of Home Affairs had formed a committee to work on the issue. The committee reviewed the matter and sent a letter to the ministry. The ministry then forwarded the letter to the BTRC and other relevant institutions with instructions to investigate. Some law enforcement agencies have also been informed of the matter. He said he hoped a decision would be reached within the next month or two.

According to a news report, the NTMC sent a letter to the Ministry of Home Affairs on the matter in April 2024. The letter stated that citizens’ NID cards and call records were being sold in 789 social media groups. The investigation found that the information had been collected using the login credentials and passwords of a police superintendent from the Anti-Terrorism Unit and an assistant police superintendent from RAB-6, a division of the Rapid Action Battalion, or RAB, an elite Bangladeshi paramilitary and law enforcement force. A constable from the cybercrime wing admitted involvement in selling sensitive call records in exchange for money.

Sabir said it is the responsibility of the National Cyber Security Agency (NCSA) to monitor whether institutions handling sensitive information are ensuring proper security. He questioned whether the agency is properly fulfilling that responsibility.

In many cases, an employee may not even think that this is confidential data, that it cannot be leaked and that doing so could violate someone else’s privacy. It raises doubts about whether institutions’ employees even have this basic awareness. Sumon Ahmed Sabir

NCSA’s director general, Md Taibur Rahman, initially agreed to an interview but was later unable to meet. With his consent, questions were sent to him via WhatsApp. He had not responded by the time this report was published.

Subscriber’s NID, call list and location: Where the risks lie

There are significant risks when a national identity card, call detail records or location information falls into someone else’s hands. IT expert Sumon Ahmed Sabir said, “In Bangladesh, the NID functions as a verification tool. If someone has all the information from this NID, they can open a fake account in my name, pretend to be me and commit fraud. It is entirely possible to construct a completely false identity pretending to be me. In the digital age, this is an extremely risky matter for every person.”

“Someone could carry out fake financial transactions or illegal transactions in your name and put you in danger,” he said. “It could also create an opportunity for money to be transferred from your valid account in the future, if additional information is linked to it. All of these issues are interrelated. So the scope of the risk is extremely broad.”

Identity theft & fake accounts
A full NID lets someone impersonate the real owner, opening accounts, signing agreements or committing fraud in another person’s name.
Financial fraud
NID plus mobile financial service data can enable fraudulent transactions, or set up future access to a victim’s real accounts.
Location tracking & stalking
Tower-based location and call records, gathered over time, can reveal a person’s daily movements and routines to anyone willing to pay.
Disproportionate harm, uneven enforcement
Research shows the same leaked data creates different risks for different people, and few of Bangladesh’s documented leaks have led to real accountability.

A publication by the Electronic Privacy Information Center (EPIC), a US-based research organization, has shown that data held by data brokers can create distinct kinds of risk for survivors of domestic abuse, immigrants and government officials. In other words, the same type of personal information can cause different kinds of harm depending on who it belongs to.

Bangladesh’s Personal Data Protection Act, 2026, states that personal data collected for a specific purpose cannot be disclosed for any other purpose without that person’s consent, and that an affected individual may file a complaint with the relevant authority if their rights are violated. The law includes provisions for administrative fines for failing to fulfill data protection and security responsibilities. In certain cases, those fines can reach 2.5 million taka.

68
documented data leak incidents in Bangladesh were reviewed by the Tech Global Institute in a study, which found that there are very few examples of effective legal action being taken against institutions or individuals responsible for data leaks.

To seek comment on the sale of personal information, Dismislab contacted the Election Commission, the National Identity Registration Wing, the NTMC and the NCSA.

Mohammad Abdul Momin Sarkar, director of public relations at the Election Commission, said a written application would need to be submitted to the commission to obtain a statement on the matter. Questions sent to AHM Anwar Pasha, director general of the National Identity Registration Wing, went unanswered. An NTMC official declined to comment. A subsequent interview request emailed to the agency’s additional director also went unanswered.

Methodology

For this investigation, Dismislab collected and analyzed 605 social media posts selling personal information over a one-month period. From these posts, active groups, seller accounts, contact numbers, transaction numbers and related websites were identified. To understand how the websites operated, Dismislab registered on them and reviewed publicly available domain-related information.

To test whether the information was actually being supplied, reporters posed as buyers and purchased several NID documents, CDRs and location-related information. In each test, prior consent was obtained from the person concerned, and the information received was cross-checked against their original documents or phone records.

Sensitive information obtained during the investigation was kept secure, and unnecessary personal identifiers were not disclosed in the report. Attempts were also made to obtain comments from relevant sellers, technology experts, mobile operators and government institutions.

This investigation is not a comprehensive account of the entire market. Rather, it presents a picture of the market’s scale and operating methods based on publicly visible promotions and verifiable samples identified during a defined period.