Six million Bangladeshis’ CVs on dark web to sell

A hacker group has put up about six million (60 lakh) curriculum vitae (CVs) of Bangladeshis for sale on the dark web, claiming that the data was collected from the database of Bangladeshi job portal BD Jobs.
The group, identified as ‘Madrax’, has reportedly offered the database for USD 1,000 per buyer, according to a post published on the website- DarkForums.ru at around noon on Sunday (23 August).
Madrax claimed that it has about six million CVs in its possession and that the entire database would be sold to only five individuals, with each buyer required to pay USD 1,000.
As evidence to support its claim, the group published 148 CVs as samples, which were available for download free of charge.
An analysis of the samples found that the CVs followed similar formats and appeared to have been prepared using templates associated with BD Jobs. The samples included CVs of both men and women and contained extensive personal information, including names, phone numbers, addresses, academic qualifications, training details and professional experience.
Asia Post contacted at least three individuals whose CVs appeared among the samples. Their information have been matched as the CVs found on the bidding.
They said that their CVs are kept to BD Jobs.
The individuals said they had no knowledge of their CVs being transferred to any third party. They also said BD Jobs had not informed them about any such incident.
Meanwhile, BD Jobs CEO Fahim Mashrur said the company had not found any evidence that its database had been breached.
“We have not yet known that our database has been breached. If such [a breach] happened, we would have known it first,” he told Asia Post.
He said employers regularly purchase CVs from BD Jobs, and information from some CVs could potentially have reached other parties through such transactions.
“Besides, many people keep their CVs publicly available on LinkedIn. The information from some CVs may go into other hands from there,” Mashrur said.
He also suggested that someone could be using the BD Jobs name to make money.
“Using our name, earnings may be handsome for many. Such people may do these using our name,” he said.
However, cyber security experts and ethical hackers have questioned the explanation.
Ethical hacker and Cyber71 Director Abdullah Al Jaber said it would not be a straightforward matter for someone have purchased six million CVs from BD Jobs, and subsequently put them up for sale on the dark web.
“Some people purchase six million CVs from BD Jobs and then put them up for bidding on the dark web—it is not such a simple thing,” he told Asia Post.
He also dismissed the possibility that the database could have been obtained simply by scraping LinkedIn.
“Obtaining a huge database of six million CVs from LinkedIn through scraping and then selling it on the dark web is not realistic at all,” he said.
He noted that LinkedIn’s security system might be stronger than that of a Bangladeshi organisation.
Al Jaber warned that if the data is genuine, the exposure of such personal information could pose serious risks to the individuals concerned.
“What is behind your CV? Your full name, current and permanent address, personal mobile phone number, email account, study details, present and previous job information—everything,” he said.
“These sensitive data are now directly in the hands of cyber criminals,” he added.
According to the cyber security expert, criminals could use the information to create fake identities, commit banking and financial fraud, launch spam or phishing attacks, and carry out other crimes using victims’ names and addresses.
“They can create fake identities with your data. They can commit bank or financial fraud, spam or phishing attacks,” he said.
“They can even commit dangerous criminal acts using your name and address, of which you may have no idea,” he warned.
Al Jaber also questioned the level of data security maintained by organisations holding large amounts of citizens’ personal information.
“My question is why data security is in such a vulnerable condition? BD Jobs should be held accountable on this issue,” he said.
He urged people to remain highly cautious about calls, messages and links received from unidentified sources, whether through mobile phones or email.
He also advised users not to click on suspicious links or download attachments received through unfamiliar phone numbers or email accounts.


