Personal information of ordinary citizens has emerged as a commodity in an online market, with National Identity Card (NID) details, Call Detail Records (CDRs), mobile phone locations, SMS records, TINs, passport copies and mobile financial service account statements reportedly being sold through Facebook, websites, Telegram and WhatsApp.
Information verification organisation DismissLab, in an investigation, identified 10 active websites offering such information for sale and found more than 600 related advertisements on Facebook within a month.
While investigating the sale of voter lists in June, DismissLab researchers found an advertisement offering personal information in the comments section of a Facebook post. A search using the term ‘sign copy’ produced 675 posts, of which 605 published between June 15 and July 15 contained offers to sell personal information.
Following one such advertisement, researchers located a Telegram group named ‘Voter List’ and posed as prospective buyers. After providing a mobile phone number and paying Tk500, they received a PDF copy of the NID card associated with the number within 17 minutes.
The information, including the name, photograph and date of birth, matched the SIM owner. Even the person’s mother’s name, which had reportedly been corrected two months earlier, appeared updated in the document.
Another account in the group, identified as ‘Help BD’, advertised NID, birth and death registration records, mobile locations, CDRs, SMS lists, IMEI numbers, TINs, police clearance certificates, passport copies and land development tax receipts.
On June 25, DismissLab contacted the administrator and sought a three-month CDR of a Grameenphone number. After paying Tk1,050, the researchers received the file within two and a half hours. A comparison of the 20 most recent contact numbers, call times and call types with the customer's actual call history found the information to be consistent, according to the investigation.
In another instance, a website provided the last active time, mobile tower-based location, an address and a Google Maps link for a Grameenphone number within 16 minutes of payment.
DismissLab identified at least 112 mobile numbers being used to communicate with prospective buyers through such advertisements and found 36 active Facebook groups repeatedly offering personal information.
The investigation also found that many sellers were intermediaries rather than primary sources. They allegedly purchased information from other websites or groups and resold it at a higher price.
The owner of a website in Chandpur told DismissLab that he bought mobile customers’ call lists for Tk800 and resold them for Tk900. He also claimed that bKash statements were available for Tk4,500.
The seller further claimed that he collected information from a group which used an API to breach the security of a government server and obtain data. DismissLab, however, said it could not independently verify the claim.
According to the investigation, advertisements for personal information have been circulating online since at least 2023, while similar promotional videos were found on YouTube as early as March 2025.
Experts warn that such data can expose individuals to surveillance, harassment and fraud. CDRs can reveal whom a person contacted, when and for how long, while they may also contain IMEI and mobile tower information.
IT expert Sumon Ahmed Sabir said, “It is possible to know a person’s communication and movement pattern through call detail records and location information.”
“Therefore, there is a risk of using this information for surveillance, harassment or fraud,” he said.