Monday , September 14 2026
Bdjobs

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about six million job seekers in Bangladesh. They claim to have taken this data from Bdjobs, the top online job website in the country.

The claim appeared on the dark web and was later reported by Bangladeshi media. The reports say the dataset has CVs and personal details of millions of jobseekers. The attackers are said to have sold the data and claimed it came from Bdjobs.

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

What Data Is Allegedly Exposed?

According to reports citing the hacker group’s claims, the dataset may contain information commonly included in jobseekers’ CVs, including:
Full names
Mobile phone numbers
Email addresses
Residential information
Educational qualifications
Employment history
Professional skills and training information

The size of the claimed dataset—around six million CVs—could make the event important if confirmed.

Bdjobs Rejects Breach Claims

Bdjobs has denied claims about a security breach on its platform and asked users not to share unverified information.

The company’s privacy policy says that Bdjobs collects personal details like names, email addresses, phone numbers, and CVs for its hiring services. The company also mentions that it uses security methods like encryption and access controls to keep user data safe. However, it admits that no online storage or transmission can be fully secure.

Potential Risks for Jobseekers

If the dataset is genuine and contains current personal information, affected individuals could face increased risks of:
Phishing and targeted email attacks
Job-scam campaigns
Identity impersonation
Social-engineering attacks
Malicious calls and SMS messages
Credential theft and account takeover attempts

Jobseekers should be careful of unexpected messages that say they have job offers, interview invitations, CV checks, or requests for payments related to hiring.

What Users Should Do

Until the claim is independently verified, Bdjobs users should:
Avoid clicking suspicious links received through email, SMS or messaging platforms.
Never provide passwords, OTPs, banking information, or payment details to unknown recruiters.
Be cautious of unexpected calls claiming to represent employers.
Review important accounts for suspicious login activity.
Change passwords if the same password has been reused across multiple services.
Treat unsolicited job offers requiring registration or processing fees as potential scams.

Directorate of Secondary and Higher Education data breach claim

A hacker posted 390k data claimed to be Bangladesh’s Directorate of Secondary and Higher Education. The hacker also threatened to publish full database of DSHE on a secret online crime forum.

Summary: 

The actor claims the database contains more than 390,000 records
Allegedly exposed information includes employee names, dates of birth, phone numbers and email addresses
More sensitive fields reportedly include National ID (NID) numbers, bank account numbers and salary information
Education-sector data allegedly includes school codes and MPO codes
The actor states that the organization was contacted before publication but allegedly did not respond
A download link for the purported database has been publicly shared in the forum post
The actor describes this as their “second public drop” and indicates that additional releases are planned.

The claim should now be treated as a threat actor allegation until independently verified. If real, the mix of government worker ID info, NIDs, bank details, and salary records would be very sensitive. It could lead to identity theft, money fraud, targeted phishing, and fake government employee cases.

The actor talks about a “second public drop,” which hints at a new data leak may come in the coming days.

Related news:

Check Also

153 Million Driver’s License Surfaced on Dark Web: FBI Starts Investigation

The FBI’s New Orleans field office has opened an investigation into the suspected source of …