Monday , October 5 2026
Bdjobs

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about six million job seekers in Bangladesh. They claim to have taken this data from Bdjobs, the top online job website in the country.

The claim appeared on the dark web and was later reported by Bangladeshi media. The reports say the dataset has CVs and personal details of millions of jobseekers. The attackers are said to have sold the data and claimed it came from Bdjobs.

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

What Data Is Allegedly Exposed?

According to reports citing the hacker group’s claims, the dataset may contain information commonly included in jobseekers’ CVs, including:
Full names
Mobile phone numbers
Email addresses
Residential information
Educational qualifications
Employment history
Professional skills and training information

The size of the claimed dataset—around six million CVs—could make the event important if confirmed.

Bdjobs Rejects Breach Claims

Bdjobs has denied claims about a security breach on its platform and asked users not to share unverified information.

The company’s privacy policy says that Bdjobs collects personal details like names, email addresses, phone numbers, and CVs for its hiring services. The company also mentions that it uses security methods like encryption and access controls to keep user data safe. However, it admits that no online storage or transmission can be fully secure.

Potential Risks for Jobseekers

If the dataset is genuine and contains current personal information, affected individuals could face increased risks of:
Phishing and targeted email attacks
Job-scam campaigns
Identity impersonation
Social-engineering attacks
Malicious calls and SMS messages
Credential theft and account takeover attempts

Jobseekers should be careful of unexpected messages that say they have job offers, interview invitations, CV checks, or requests for payments related to hiring.

What Users Should Do

Until the claim is independently verified, Bdjobs users should:
Avoid clicking suspicious links received through email, SMS or messaging platforms.
Never provide passwords, OTPs, banking information, or payment details to unknown recruiters.
Be cautious of unexpected calls claiming to represent employers.
Review important accounts for suspicious login activity.
Change passwords if the same password has been reused across multiple services.
Treat unsolicited job offers requiring registration or processing fees as potential scams.

Directorate of Secondary and Higher Education data breach claim

A hacker posted 390k data claimed to be Bangladesh’s Directorate of Secondary and Higher Education. The hacker also threatened to publish full database of DSHE on a secret online crime forum.

Summary: 

The actor claims the database contains more than 390,000 records
Allegedly exposed information includes employee names, dates of birth, phone numbers and email addresses
More sensitive fields reportedly include National ID (NID) numbers, bank account numbers and salary information
Education-sector data allegedly includes school codes and MPO codes
The actor states that the organization was contacted before publication but allegedly did not respond
A download link for the purported database has been publicly shared in the forum post
The actor describes this as their “second public drop” and indicates that additional releases are planned.

The claim should now be treated as a threat actor allegation until independently verified. If real, the mix of government worker ID info, NIDs, bank details, and salary records would be very sensitive. It could lead to identity theft, money fraud, targeted phishing, and fake government employee cases.

The actor talks about a “second public drop,” which hints at a new data leak may come in the coming days.

Related news:

Check Also

JadePuffer

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal …