National Identity Card (NID) details, call records, mobile phone locations, SMS data, passport information and even mobile financial service statements are allegedly being offered for sale online for as little as a few hundred or thousand taka.
An investigation by fact-checking and verification platform DismissLab has uncovered what it describes as an online marketplace where sensitive personal information is openly advertised and sold through Facebook, Telegram, WhatsApp and dedicated websites.
The investigation identified 10 active websites offering personal data for sale. On Facebook alone, researchers found more than 600 advertisements promoting such services within a month.
The data being offered include copies of NIDs, call detail records (CDRs), mobile locations, SMS lists, IMEI numbers, TIN information, birth and death registration records, police clearance certificates, passport copies and land development tax receipts.
DismissLab first encountered advertisements for personal data while investigating the sale of voter lists in June.
A search for the term “sign copy” produced 675 Facebook posts, including 605 published between June 15 and July 15 that offered personal information for sale.
Following one such post, researchers located a Telegram group named “Voter List”.
Posing as buyers, they contacted a seller advertising NID information. After providing a mobile phone number and paying Tk500, the researchers received a PDF copy of the subscriber’s NID within 17 minutes.
The name, photograph and date of birth matched those of the actual subscriber. The document also contained the subscriber’s mother’s recently corrected name, although the correction had been made only two months earlier.
The same Telegram group carried advertisements from an account named “Help BD”, offering NIDs, birth and death registration records, mobile locations, CDRs, SMS lists, IMEI numbers, TIN information, police clearance certificates, passport copies and land tax receipts.
On June 25, researchers requested three months of CDR data for a Grameenphone number.
After paying Tk1,050, they received the file within about two and a half hours.
DismissLab compared the 20 most recent contact numbers, call times and call types in the file with the subscriber’s actual call history.
Experts say CDRs can reveal whom a person communicated with, when the communication took place, how long it lasted and whether a call was incoming or outgoing.
The investigation also found websites offering mobile location information.
Researchers requested the location of a Grameenphone number and, within 16 minutes of payment, received its latest active time, mobile tower-based location, an address and a Google Maps link.
Such information could potentially be used to track an individual’s movements and identify locations they frequently visit.
Following leads from Facebook, Telegram and WhatsApp, DismissLab identified 10 active websites displaying price lists for NID information, birth registration records, TIN details, CDRs and mobile locations.
Researchers also found 112 different mobile phone numbers used in advertisements and 36 active Facebook groups repeatedly offering personal data.
The investigation suggests that many social media sellers may themselves obtain information from websites or other groups before reselling it to customers.
The operator of a Chandpur-based website told DismissLab that he buys a mobile subscriber’s call list for Tk800 and resells it for Tk900. He also claimed that a bKash statement could be obtained for Tk4,500.
The seller claimed that his source was a group using an API to breach government servers and collect data. DismissLab, however, said it could not independently verify the claim.
The apparent availability of sensitive information online has raised serious concerns among victims about how their personal data reached these sellers.
One victim, who requested anonymity, said, “If information submitted to government systems can be obtained and sold for a few hundred taka, where is the security for ordinary citizens?”
Another said: “I cannot understand how a stranger can find out whom I have spoken to and when. This is deeply disturbing.”
Information technology specialist Suman Ahmed Sabir said access to CDR and location data could expose a person’s communication and movement patterns, creating serious risks of surveillance, harassment and fraud.
Cybersecurity and information technology specialist Arif Mahiuddin said: “The leakage of personal information is not merely a privacy violation; it can enable identity theft, financial fraud, blackmail and other targeted cybercrimes.”
DismissLab found advertisements for personal data dating back to 2023, while a YouTube video published in March 2025 also advertised similar services.
The findings raise a crucial question: How are recently updated government and private-sector records reaching online sellers?
NID, SIM registration, call records, passport, TIN and financial information are normally held within controlled systems.
If such data is being accessed without consent, identifying the source of the leak is as important as prosecuting those selling it.
What began as scattered online advertisements now appears to have developed into a commercial marketplace for citizens’ most sensitive information.
For Tk500, someone may be able to buy your identity. For Tk1,050, your communications. And in just 16 minutes, potentially your whereabouts.


