Pathao, one of the country's leading ride-hailing and delivery platforms, confirmed that malicious actors obtained personal information of nearly 1.9 crore users following a cybersecurity breach on October 4.
In a official statement released on October 7, the company stated that it immediately took critical systems offline upon detecting the unauthorized access as a precaution to safeguard platform integrity.
Although core services were restored shortly after, intermittent technical disruptions remain possible as stabilization work continues.
"We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors," Pathao said in its statement.
The firm did not specify the total number of compromised accounts or reveal the technical vulnerability exploited by the attackers. Furthermore, it remains undisclosed whether sensitive financial data, passwords, or government identification documents were exposed during the breach.
Pathao engaged external cybersecurity consultants to fortify system controls, contain the incident, and restore database security. Relevant state regulatory authorities have been notified, and cooperation with ongoing investigations is underway.
Security Advisory Issued
Following the breach, Pathao urged users to exercise caution regarding unsolicited messages, calls, or links claiming to represent the platform.
"Users should never share passwords, PINs or OTPs in response to such communications," the statement warned, advising customers and partners to rely exclusively on official channels for verified updates.
The company has not verified separate online claims alleging a broader data exfiltration, adding that further findings will be shared upon verification. Pathao issued an apology to users, drivers, and merchant partners for the service disruption.
-SA