Two senior officers working for anti-terror police in Bangladesh allegedly collected and bought categorized and private info of residents to criminals on Telegram, TechCrunch has discovered.
The information allegedly bought included nationwide identification particulars of residents, cellphone name information and different “categorized secret info,” in line with a letter signed by a senior Bangladeshi intelligence official, seen by TechCrunch.
The letter, dated April 28, was written by Brigadier Basic Mohammad Baker, who serves as a director of Bangladesh’s Nationwide Telecommunications Monitoring Heart, or NTMC, the nation’s digital eavesdropping company. Baker confirmed the legitimacy of the letter and its contents in an interview with TechCrunch.
“Departmental investigation is ongoing for each the instances,” Baker stated in a web-based chat, including that the Bangladeshi Ministry of House Affairs ordered the affected police organizations to take “essential motion in opposition to these officers.”
The letter, which was initially written in Bengali and addressed to the senior secretary of the Ministry of House Affairs Public Safety Division, alleges the 2 police brokers accessed and handed “extraordinarily delicate info” of personal residents on Telegram in alternate for cash.
Based on the letter, the police brokers have been caught after investigators analyzed logs of the NTMC’s techniques and the way typically the 2 accessed it.
The letter reveals the identification of the officers. One of many accused is a police superintendent serving with the Anti-Terrorism Unit (ATU). The opposite is an assistant police superintendent deputy on the Fast Motion Battalion, also referred to as RAB 6, a controversial paramilitary unit that the U.S. authorities sanctioned in 2021 over allegations that the unit is linked to lots of of disappearances and extrajudicial killings. TechCrunch shouldn’t be naming the 2 individuals who have been accused because it’s unclear if they’ve been charged below the nation’s authorized system.
The NTMC is a authorities intelligence company established below Bangladesh’s Ministry of House Affairs. The company’s core activity is to watch all telecommunications site visitors and intercept cellphone and internet communications to detect and forestall threats to nationwide safety.
Organizations like Human Rights Watch and Freedom Home have criticized the NTMC for missing safeguards in opposition to abuses, each in opposition to free speech in addition to privateness. Over time, NTMC procured refined expertise from firms in Israel, which Bangladesh doesn’t formally acknowledge, in addition to different Western nations, to conduct mass surveillance largely on opposition get together members, journalists, civil society members and activists.
As a part of its mission, the NTMC runs the Nationwide Intelligence Platform, or NIP, an inner authorities internet portal that holds categorized citizen info, like nationwide identification particulars, cellphone registration and cell knowledge information, felony profiles and different info.
Numerous regulation enforcement and intelligence businesses have consumer accounts on the NIP portal supplied by the NTMC.
NTMC’s personal investigation concluded that the brokers used the NIP platform extra ceaselessly than others, and accessed and picked up info that was not related to them.
“Contemplating the context, such irrelevant entry and illegal handover of extraordinarily delicate categorized knowledge ought to be investigated to establish everybody concerned on this and we additionally request for acceptable motion in opposition to all these recognized/concerned,” the letter learn.
Baker instructed TechCrunch that there have been a “variety of Telegram channels,” including that one in all them was referred to as BD CYBER GANG.
TechCrunch couldn’t establish the precise channel on Telegram.
Contact Us
Do you’ve extra details about this incident, or comparable incidents? From a non-work system, you’ll be able to contact Lorenzo Franceschi-Bicchierai securely on Sign at +1 917 257 1382, or by way of Telegram, Keybase and Wire @lorenzofb, or electronic mail. You too can attain out to Zulkarnain Saer Khan on Sign at +36707723819, or on X @ZulkarnainSaer. You can also contact TechCrunch by way of SecureDrop.
Baker instructed TechCrunch that it seems that the 2 brokers despatched the data to the administrator of at the very least one Telegram group, who then tried to promote it.
Baker stated that the 2 brokers have been notified of the investigation.
Due to the investigation, all NIP customers from ATU and RAB 6 have had their entry suspended “till the concerned officers are recognized, and correct motion is taken,” in line with the letter.
Baker confirmed the suspended entry, saying that if brokers “want any info for investigation functions they will accumulate by Police and RAB HQ.”
Spokespeople for Bangladesh’s Ministry of House Affairs and ATU didn’t reply to a number of requests for remark. An individual figuring out solely as an “operations officer” at RAB 6 instructed TechCrunch that the company had no remark.
Final 12 months, a safety researcher discovered that the NTMC was leaking folks’s private info on an unsecured server. The leaked knowledge included real-world names, cellphone numbers, electronic mail addresses, areas and examination outcomes, in line with Wired. One other Bangladeshi authorities company, the Workplace of the Registrar Basic, Beginning & Dying Registration, additionally leaked residents’ delicate knowledge final 12 months, as TechCrunch reported on the time.
In each instances, the leaks have been discovered by Viktor Markopoulos, a researcher who works at Bitcrack Cyber Safety.
Whereas these have been important instances of knowledge publicity, this incident allegedly involving the ATU and RAB 6 brokers is doubtlessly extra damaging, provided that the brokers allegedly bought info on-line in an try and revenue from their privileged entry to categorized private info.
Though the incident is below investigation, a well-placed supply inside the authorities instructed TechCrunch that there are nonetheless officers who’re providing to promote residents’ knowledge.