A CV is usually treated as a piece of paper that helps someone get a job. We write our details, send it to an employer, and move on. But in the digital age, a CV is much more than an application for employment. It is a compact map of a person’s identity. It tells someone where we live, where we studied, where we worked, how to contact us and, sometimes, what we have been doing for years.
That is precisely why the recent controversy over the alleged sale of millions of Bangladeshi job seekers’ CVs on the dark web should worry us far more than an ordinary cyber security incident.
A hacker group calling itself Madrex has reportedly claimed possession of the CVs of around six million users of the popular Bangladeshi job platform BDJobs and has advertised the information for sale. BDJobs has denied the claim.
Yet, 148 CV samples were reportedly published as evidence of the alleged breach. At this point, neither a hacker’s claim nor an institutional denial should be treated as the final word. The important question is not who is telling the truth but whether the public has a reliable mechanism through which such a claim can be independently verified.
This is where our digital culture reveals a troubling weakness. When sensitive personal information is allegedly exposed, the immediate response often becomes a contest of statements.
One side makes a claim, another denies it, and the public is expected to decide whom to believe. But data security cannot be established through public relations. It requires technical investigation and institutional transparency.
If the claim is false, an independent investigation should establish that clearly. If the claim is true, the same investigation should determine how the information was obtained, what information was compromised, and how many people may be at risk.
The larger problem is that we continue to think of personal information as if it were an ordinary administrative resource. It is not. A database containing millions of CVs is potentially a database of millions of identities. Each individual record may contain a person’s full name, telephone number, email address, residential information, educational history, employment history, training and other professional details.
When these pieces are assembled, they become far more valuable than any individual piece of information. A criminal does not need a person’s entire life story. A sufficiently detailed digital profile may be enough to impersonate that person convincingly.
This is where the alleged CV leak becomes particularly disturbing.
A fraudster armed with a person’s professional history can design a much more convincing scam than someone who merely knows a telephone number. A fake recruiter can mention the person’s university, profession, or previous employer. A fraudulent job offer can be tailored to the individual’s career interests. A phishing message can appear to come from an organization the person is likely to trust. The victim may not even realize that the information used to deceive them came from a compromised database.
The European Data Protection Board recognizes identity theft, fraud, and financial loss among the potential consequences of personal data breaches. That understanding is important because it shifts the discussion away from the narrow language of passwords, servers, and firewalls.
The ultimate victim of a data breach is not a database. It is a human being.
A compromised database can be repaired, a password can be changed and a server can be replaced. But once personal information enters the criminal ecosystem, it may be impossible to retrieve it.
If someone steals a document from an office, we understand that something valuable has been taken. Yet when millions of digital records are copied, we often describe the incident as a technical problem. The language itself is misleading. Data theft is theft, even when nothing physical disappears from a building.
The controversy also raises a more uncomfortable question: What responsibility does an organization assume when it collects our information? When people create accounts on job portals, banks, hospitals, universities, or government platforms, they surrender information because they need a service. They do not surrender ownership of their identity.
The organization becomes a custodian of that information, and custodianship creates responsibility. This responsibility cannot end with having a password policy or installing a firewall. Serious data protection requires knowing what information is being collected and why, limiting unnecessary collection, controlling who can access sensitive databases, encrypting information, monitoring unusual activity, conducting regular security assessments, and maintaining a credible response plan.
It also requires knowing what to do when something goes wrong. Security is not a product that an organization purchases once. It is a continuous institutional practice.
The developed world has increasingly recognized this principle. The underlying philosophy is simple: Institutions that collect valuable information must also prepare for the possibility that someone will try to steal it.
Bangladesh needs to develop the same culture of responsibility. Too often, cyber security is treated as the IT department’s problem. It is not. It is a management issue, a legal issue, and increasingly a public-interest issue.
The person responsible for collecting millions of records cannot wash their hands of responsibility by saying that a technical team manages the server. The technical team may operate the system, but the institution carries the responsibility.
There is another reason this particular controversy deserves serious attention. Job seekers are among the people least capable of protecting themselves from the consequences of a data breach. Many are young graduates desperate for employment. They are already vulnerable to fraudulent recruitment, fake interviews, demands for registration fees, and other forms of exploitation. If detailed CV information becomes available to criminals, an already vulnerable group could become even easier to target.
The answer, however, is not to stop sharing information online. Modern life makes that impossible. The answer is to recognize that information has value and therefore demands protection proportional to that value.
We have spent years teaching people to protect their passwords. We now need to teach institutions to protect the information people are forced to entrust to them.
This is ultimately a question of digital dignity. A person should not have to wonder whether the information submitted in good faith to find employment will someday appear for sale in an underground marketplace.
Nor should citizens have to depend entirely on corporate assurances when serious allegations of data exposure emerge. They deserve transparent answers, independent verification, and meaningful protection.
The Madrex claim may eventually prove to be exaggerated, partially true, or completely false. That is precisely why it must be investigated rather than simply argued about.
If the claim is false, an independent investigation can restore confidence. If it is true, the investigation can help identify the breach, protect potential victims, and prevent a recurrence. Either way, the public interest is served by finding the facts.
We often repeat that information is power. But information becomes dangerous when it is concentrated in the hands of those who have no right to possess it. The real lesson of the alleged CV leak is not that hackers have become more dangerous. It is that institutions entrusted with our information must become far more responsible.
A CV may help someone get a job. But in the wrong hands, the same CV can help someone steal a person’s identity. We need to understand that difference before the next six million records become another statistic.
HM Nazmul Alam is an academic, journalist, and political analyst based in Dhaka, Bangladesh. Currently he teaches at IUBAT.


