The details of a significant number of Bangladeshi bank cards are for sale on the dark web, the criminal marketplace layer of the internet, according to a year-long study by the government's cyber-security agency, BGD e-GOV Computer Incident Response Team. Of roughly 2,000 cards its threat-intelligence unit analysed, 46.3 per cent of classic cards, 31.24 per cent of gold, 5.71 per cent of platinum and 5.3 per cent of prepaid cards had information circulating, in some cases with the cardholder's password, transactions and e-mail.
How the data gets there
CIRT's director, Tarique M Barkatullah, put the blame in two places. First, customers: card use has surged since the pandemic, and much of the leakage traces to weak passwords and compromised phones and computers. Second, the banks: some run outdated network equipment, low-grade devices and no patch management. The report found that about 99 per cent of banking institutions expose at least one vulnerable service to the internet, often without knowing it, that 75 per cent of cases involve insecure use of a phone or computer, and that home and office routers are the single riskiest device. IBM X-Force data for 2021 says 70 per cent of cyber-attacks on financial institutions worldwide target banks.
The scale of what is at stake
Bangladesh Bank counted 2.72 crore debit cards, 19.4 lakh credit cards and 16.4 lakh prepaid cards in May 2022, with monthly transactions of about Tk 26,050 crore on debit cards, Tk 2,371 crore on credit and Tk 177 crore on prepaid. Selim R F Hussain, chairman of the Association of Bankers, Bangladesh and managing director of BRAC Bank, said CIRT's alerts help: when a card is found leaked, the bank blocks it immediately and issues a replacement free of charge. "The risk cannot be brought to zero," he said, "but banks that build strong security fastest will be best for their customers."
What a cardholder should do
- Turn on transaction alerts by SMS and app, and read them. A Tk 1 test charge from a foreign merchant is the classic sign your card is being probed.
- Switch off online and international transactions in the bank app when you are not using them; most local banks now allow this per card.
- Never type card details on a site reached from a Facebook ad or SMS link. Type the merchant's address yourself.
- Change your online-banking password if it is reused anywhere, and use an authenticator app, not only SMS OTPs.
- Update your router's firmware and its admin password; the default one is printed on the box and on the internet.
- Ask your bank whether your card appears in CIRT's lists; you are entitled to a free replacement if it does.
CIRT's recommendations to the banks, vendor access control, staff-device restrictions, mandatory strong passwords and continuous monitoring, are standard practice elsewhere. That they needed saying is the finding.




