← Shwapno

2025 Shwapno — customer database intrusion; ~40 lakh records, delayed disclosure

2025 4.0M records affected Share on X

Data compromised

Investigative reporting cites ~410 GB including names, phone numbers, and purchase histories of roughly forty lakh (4 million) registered Shwapno customers

Technical writeup

Bangladesh retail breach — attested by investigative journalism July 2026. The Daily Star reported hackers broke into Shwapno's customer database on August 19, 2025, exfiltrating about 410 gigabytes containing names, phone numbers, and purchase histories tied to roughly forty lakh (four million) registered customers, with a $1.5 million ransom demand refused. Shwapno secured systems but did not notify customers for seven months; when stolen data spread on the dark web in March 2026, public awareness preceded a police report. The incident illustrates gaps in Bangladesh's new data protection framework, which investigative coverage notes lacks mandatory breach-notification requirements. BreachHistory indexes the four-million figure from reputable reporting; formal company victim counts may differ.

Root cause

Hackers intruded Shwapno customer database August 19, 2025; ransom refused; data surfaced on dark web March 2026 before broad customer notification per investigative reporting

References