Monday , August 24 2026
Bdjobs

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about six million job seekers in Bangladesh. They claim to have taken this data from Bdjobs, the top online job website in the country.

The claim appeared on the dark web and was later reported by Bangladeshi media. The reports say the dataset has CVs and personal details of millions of jobseekers. The attackers are said to have sold the data and claimed it came from Bdjobs.

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

What Data Is Allegedly Exposed?

According to reports citing the hacker group’s claims, the dataset may contain information commonly included in jobseekers’ CVs, including:
Full names
Mobile phone numbers
Email addresses
Residential information
Educational qualifications
Employment history
Professional skills and training information

The size of the claimed dataset—around six million CVs—could make the event important if confirmed.

Bdjobs Rejects Breach Claims

Bdjobs has denied claims about a security breach on its platform and asked users not to share unverified information.

The company’s privacy policy says that Bdjobs collects personal details like names, email addresses, phone numbers, and CVs for its hiring services. The company also mentions that it uses security methods like encryption and access controls to keep user data safe. However, it admits that no online storage or transmission can be fully secure.

Potential Risks for Jobseekers

If the dataset is genuine and contains current personal information, affected individuals could face increased risks of:
Phishing and targeted email attacks
Job-scam campaigns
Identity impersonation
Social-engineering attacks
Malicious calls and SMS messages
Credential theft and account takeover attempts

Jobseekers should be careful of unexpected messages that say they have job offers, interview invitations, CV checks, or requests for payments related to hiring.

What Users Should Do

Until the claim is independently verified, Bdjobs users should:
Avoid clicking suspicious links received through email, SMS or messaging platforms.
Never provide passwords, OTPs, banking information, or payment details to unknown recruiters.
Be cautious of unexpected calls claiming to represent employers.
Review important accounts for suspicious login activity.
Change passwords if the same password has been reused across multiple services.
Treat unsolicited job offers requiring registration or processing fees as potential scams.

Directorate of Secondary and Higher Education data breach claim

A hacker posted 390k data claimed to be Bangladesh’s Directorate of Secondary and Higher Education. The hacker also threatened to publish full database of DSHE on a secret online crime forum.

Summary: 

The actor claims the database contains more than 390,000 records
Allegedly exposed information includes employee names, dates of birth, phone numbers and email addresses
More sensitive fields reportedly include National ID (NID) numbers, bank account numbers and salary information
Education-sector data allegedly includes school codes and MPO codes
The actor states that the organization was contacted before publication but allegedly did not respond
A download link for the purported database has been publicly shared in the forum post
The actor describes this as their “second public drop” and indicates that additional releases are planned.

The claim should now be treated as a threat actor allegation until independently verified. If real, the mix of government worker ID info, NIDs, bank details, and salary records would be very sensitive. It could lead to identity theft, money fraud, targeted phishing, and fake government employee cases.

The actor talks about a “second public drop,” which hints at a new data leak may come in the coming days.

Related news:

Check Also

card

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from …