Pathao confirmed this week that attackers took users' names, email addresses and phone numbers after a 4 October attack. I run AliasFleet, an email-alias service: one forwarding address per site, so a leak names its source. No victim number does not mean a small breach. Those three fields are the complete kit for impersonation, and they are already out.
The disclosure
The statement landed on 7 October on Pathao's official Facebook page, and TBS News and the Dhaka Tribune picked it up. Pathao says it found the incident on 4 October, pulled critical systems offline straight away, and brought services back soon after, with some intermittent problems continuing.
"We understand that certain personal information, including names, email addresses and phone numbers, was obtained by malicious actors."
Here is where the confirmed facts end and the unknowns begin:
| What we know | What we don't |
|---|---|
| The disclosure: Pathao posted it on 7 October via its official Facebook page | How many people are affected: the company has released no number |
| The timing: the incident was detected on 4 October and hit services platform-wide | How the attackers got in, or how long they stayed |
| The fields: names, email addresses and phone numbers | Whether passwords, payment data or ID documents were taken |
| The response: critical systems taken offline, outside security experts brought in, the relevant authorities informed | Whether the stolen data is being traded or will surface publicly |
| The warning: be wary of unsolicited messages, calls or links claiming to be Pathao; never share passwords, PINs or OTPs with them | Anything in the attackers' own claims (next section) |
The $400,000 claim nobody can verify
A dark web listing, surfaced by the Daily Dark Web monitoring platform, claims about 133 gigabytes of Pathao data covering roughly 19 million accounts. The claimed contents go far past the confirmed three fields: NID numbers, driving licence records, photographs, home addresses, location data and financial records. The ask is $400,000, with a threat to publish the lot.
The Dhaka Tribune reports the claim and immediately hedges it: the authenticity and extent could not be independently verified. Pathao has confirmed none of it. Not the 19 million figure. Not the NID numbers. Not the licences or the money.
Attackers inflate. That is how ransom works: the bigger the haul sounds, the more likely someone pays. But it might also be true. The gap between three confirmed fields and a claimed 19-million-account haul is exactly where criminals operate, and you do not get to wait for Pathao to close it before deciding what to do.
Why those three fields are enough
Nobody shrugs when passwords leak. Everyone shrugs when it is "just" contact details. That shrug is wrong. A name plus a phone number plus an email address is all a caller or texter needs to sound like your ride-hailing app, your bank's fraud desk, or Pathao support itself.
Pathao made the same point in its own warning, with different words: treat unsolicited messages, calls or links claiming to represent Pathao with suspicion, and never hand over passwords, PINs or OTPs to them. The company has not said impersonation attempts are already happening. It does not need to. The confirmed fields are the ingredients, and they are out.
A call or text that knows your name, your number and your email is proving it has the leaked file, not that it is Pathao. Pathao itself said never to share passwords, PINs or OTPs in reply to such messages, so anything that asks for them is fraud. Open the Pathao app or type the site address yourself. No link, no caller ID, no sender name does that check for you.
The one field you can make expendable
You cannot change your name after a breach. You cannot change your phone number. But the email address you typed into Pathao's signup screen was a decision, and it is the one item in the leaked record you can make expendable.
An email alias reserved for Pathao, forwarding into your real inbox, changes the impersonation math. Every message on that alias is either Pathao or somebody working the leaked file. There is no third option. A "security alert" about the breach that lands anywhere else, or asks for things the real Pathao would never request by email, has outed itself. The leak-tracing mechanism works exactly this way: the alias names the company the address escaped from. Kill the alias and the whole channel dies while your real inbox stays clean. This is not a disposable-mail trick; it is one permanent managed identity per service, the exact opposite of disposable.
If you signed up with your main address, you cannot take that back. That address has probably been yours for years, so of course it stings. What you can do is stop the list growing: one address per website means the next breach takes an address that belongs to one place only. The set-up guide takes about two minutes, and ten aliases are free on the pricing page.
If you ride with Pathao, do this now
- Treat your name, email and phone as already circulating. The fields are confirmed taken, so act like the leak is live.
- Change your Pathao password, and change it anywhere you reused it. Passwords were not confirmed taken, but credential stuffing pairs your leaked email with passwords from other breaches.
- Switch on two-factor authentication on your email account. Every password reset flows through it, and your name, email and number are the raw material of account-recovery scams.
- Click no links and hand over no PINs, passwords or OTPs in reply to any message about this breach. Open the app or type the address yourself.
- Expect calls and texts that read your own details back to you. That proves they have the file. Hang up and ring the official number yourself.
- Check Have I Been Pwned once the incident is listed, then work through the breach-response order of operations for the rest.
What decides how this ends
Three open questions. First, whether Pathao puts a number on the victims or confirms anything past the three fields. Silence on scope is what lets the attackers' 19 million claim own the story. Second, whether the claimed dataset shows up in public or the ransom changes hands. Either event turns an unverified claim into a circulating one. Third, how the 4 October intrusion actually happened: people noticed the service disruption first and heard about the data loss three days later, which suggests the full picture took time to assemble. The investigation is still running. Your move does not change with its outcome: act on the confirmed fields now, not on whatever number comes later.
Top comments (0)