A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about six million job seekers in Bangladesh. They claim to have taken this data from Bdjobs, the top online job website in the country.
The claim appeared on the dark web and was later reported by Bangladeshi media. The reports say the dataset has CVs and personal details of millions of jobseekers. The attackers are said to have sold the data and claimed it came from Bdjobs.
What Data Is Allegedly Exposed?
According to reports citing the hacker group’s claims, the dataset may contain information commonly included in jobseekers’ CVs, including:
Full names
Mobile phone numbers
Email addresses
Residential information
Educational qualifications
Employment history
Professional skills and training information
The size of the claimed dataset—around six million CVs—could make the event important if confirmed.
Bdjobs Rejects Breach Claims
Bdjobs has denied claims about a security breach on its platform and asked users not to share unverified information.
The company’s privacy policy says that Bdjobs collects personal details like names, email addresses, phone numbers, and CVs for its hiring services. The company also mentions that it uses security methods like encryption and access controls to keep user data safe. However, it admits that no online storage or transmission can be fully secure.

Potential Risks for Jobseekers
If the dataset is genuine and contains current personal information, affected individuals could face increased risks of:
Phishing and targeted email attacks
Job-scam campaigns
Identity impersonation
Social-engineering attacks
Malicious calls and SMS messages
Credential theft and account takeover attempts
Jobseekers should be careful of unexpected messages that say they have job offers, interview invitations, CV checks, or requests for payments related to hiring.
What Users Should Do
Until the claim is independently verified, Bdjobs users should:
Avoid clicking suspicious links received through email, SMS or messaging platforms.
Never provide passwords, OTPs, banking information, or payment details to unknown recruiters.
Be cautious of unexpected calls claiming to represent employers.
Review important accounts for suspicious login activity.
Change passwords if the same password has been reused across multiple services.
Treat unsolicited job offers requiring registration or processing fees as potential scams.
Directorate of Secondary and Higher Education data breach claim
A hacker posted 390k data claimed to be Bangladesh’s Directorate of Secondary and Higher Education. The hacker also threatened to publish full database of DSHE on a secret online crime forum.
Summary:
The actor claims the database contains more than 390,000 records
Allegedly exposed information includes employee names, dates of birth, phone numbers and email addresses
More sensitive fields reportedly include National ID (NID) numbers, bank account numbers and salary information
Education-sector data allegedly includes school codes and MPO codes
The actor states that the organization was contacted before publication but allegedly did not respond
A download link for the purported database has been publicly shared in the forum post
The actor describes this as their “second public drop” and indicates that additional releases are planned.

The claim should now be treated as a threat actor allegation until independently verified. If real, the mix of government worker ID info, NIDs, bank details, and salary records would be very sensitive. It could lead to identity theft, money fraud, targeted phishing, and fake government employee cases.
The actor talks about a “second public drop,” which hints at a new data leak may come in the coming days.
InfoSecBulletin Cybersecurity for mankind
