Reliable Brokers
Online Investing
Alerts & Analysis
Easy Trading

When public data becomes a fraudster's paradise

As long as official negligence goes unchecked, the bond of trust between citizens and the state will remain fundamentally broken

Update : 27 Jul 2026, 10:38 AM

The caller on the other end spoke with the crisp, measured cadence of a senior bureaucrat. 

He introduced himself as a "deputy secretary" from the Ministry of Information and Broadcasting. 

Had he offered general pleasantries or vague institutional jargon, I would have ended the call within seconds. But he didn’t. 

Instead, he casually reeled off specifics that made me pause: The exact month two years ago when my son was enlisted as a performer at Bangladesh Betar, followed by the precise details of his recent artist grade upgrade.

Every detail was spot-on.

The punchline arrived with bureaucratic smooth-talking. 

To "disburse" the back-pay and revised remuneration tied to his upgraded grade, the ministry needed to verify a few financial credentials. 

All I had to do was provide my bank account details and debit card number over the phone.

I knew it was a scam. The caller was blocked shortly after, though I allowed the conversation to linger just long enough to see how far he would push, how far he would go to coerce those sensitive financial digits out of me. 

But as I hung up, a far more troubling question lingered in the air: How on earth did a telephone scammer acquire a granular, internal ledger of my son’s bureaucratic record from a state-run broadcasting institution?

My experience, it turns out, was far from an isolated glitch. 

It is a symptom of a systemic disease quietly metastasizing across Bangladesh’s public sector: The alarming, unvetted leakage of private data from institutions where citizens are required to hand over their most intimate details.

The anatomy of an institutional breach

Consider the unsettling reality currently unfolding at Jahangirnagar University (JU). 

Over the past six months, at least 66 students and their families have reported falling victim to organized, targeted fraud rings. 

The tactics used by these syndicates are terrifyingly personal and engineered for maximum panic.

In one instance, the father of a postgraduate chemistry student in the university’s 48th batch received a late-night call from a man claiming to be an officer with the Detective Branch (DB) of police. 

The caller claimed his son had been picked up in a drug sweep, accompanied by background sounds of a young man weeping.

The frantic father was ordered to immediately send money via mobile financial services to secure his son’s release. 

He was already on his way to the local agent shop when family members managed to reach the student, safe in his residential hall.

In other cases, scammers posed as university faculty or staff from the registrar’s office.

Calling parents directly, they claimed that technical errors were blocking the transfer of government stipends or merit scholarships. 

They asked for banking credentials and one-time passwords (OTPs) to "rectify" the issue. One family lost Tk36,000 in minutes; another lost Tk10,000.

What makes these attacks so devastating is not merely the cruelty of the extortion, but the uncanny precision of the information used to pull them off.

Callers knew the students’ full names, exact departments, academic years, residential halls, registration details, and -- crucially -- the private contact numbers of their parents.

Where did this data come from? 

The victims themselves noted that the specific contact details used by the callers were the exact ones submitted on official admission forms years prior -- information that was never meant to be public.

Routine advisories for criminal negligence

When confronted with these incidents, institutional leadership almost reflexively defaults to deflection.

Officials at Jahangirnagar University suggested that scholarship lists published on public websites might be the source, or that fraudsters were simply guessing numbers at random.

Such explanations are completely detached from reality. Public award lists do not contain parents' personal mobile numbers or non-public admission records. 

Random number generators do not magically pair a father's phone number with his child's specific academic batch and department at a state university.

The reality is far simpler and far more damaging: Personal databases maintained by public institutions are leaking like a sieve. 

Whether through unauthorized employee access, third-party vendor compromise, poor digital hygiene, or outright internal collusion, confidential records are routinely finding their way into the hands of organized criminal rings.

Yet, the administrative response remains painfully predictable. Bureaucrats issue routine warning notices instructing students and parents to "exercise caution." 

They promise to pass rogue phone numbers to the police and wash their hands of the matter.

This approach is fundamentally inadequate. Telling citizens to be vigilant while ignoring the wide-open back door through which their private data was stolen is institutional gaslighting. 

When a public university or state ministry collects personal data, it incurs a legal and moral obligation to protect it. 

Failing to safeguard that information is not an administrative oversight; it is criminal negligence.

 

Demanding accountability

We must stop treating data harvesting and financial scams as inevitable hazards of the digital age. 

They are direct consequences of institutional failure.

When young applicants submit their personal histories to a university, or when artists register their details with a state broadcaster, they hand over those details in good faith.

They trust that the institution will act as a responsible custodian. When that trust is betrayed, the institution cannot simply stand by as a passive observer.

We need to start asking hard, uncomfortable questions:

● Who has access to internal student and employee databases?
● What access logs, encryption standards, and digital protocols are actually enforced?
● What happens to hard-copy forms filled out during admissions and recruitments once they are digitized?

Answering these questions requires far more than internal committee observations or surface-level public advisories. 

It demands comprehensive, independent criminal investigations. 

Cybercrime units must trace not only the extortionists at the end of the phone line, but also the origin point where the data leaked. 

If administrative staff or system administrators failed to secure these records -- or worse, sold them -- they must be identified, prosecuted, and publicly held to account.

Until public institutions face real consequences for failing to protect the data entrusted to them, sensitive records will continue to circulate among fraudsters. 

As long as official negligence goes unchecked, the bond of trust between citizens and the state will remain fundamentally broken.

Wafiur Rahman looks after the business desk at Dhaka Tribune.

Top Brokers