Their data was searchable by phone number.
Major companies in Bangladesh still treat cybersecurity as an afterthought. Four million Shwapno customers found out what that costs.
Security is still an afterthought for large enterprises
For a decade, "Digital Bangladesh" pushed banking, retail, healthcare, and government services online at remarkable speed. Investment in the thing that keeps all that data safe did not keep pace. The warning signs were never subtle — a 2023 government exposure of an estimated 50 million citizens' data, a City Bank breach in early 2025, Titas Gas firewall access reportedly sold on the dark web.
The common thread is not sophistication on the attacker's side. It is complacency on the defender's side — security budgets cut first, incident-response plans that exist only on paper, and "we haven't been hacked yet" mistaken for a strategy. In 2026, Shwapno paid that bill in full.
The Shwapno (ACI Logistics) breach, step by step
Shwapno is not a small operation. A subsidiary of ACI Limited, it runs 800+ outlets across 63 districts and holds records for around 4 million customers. If any organisation had the resources to defend itself, it was this one. This is how it unfolded, reconstructed from reporting by The Business Standard, The Daily Star, and Bangladesh Monitor.
Reconnaissance & phishing
Analytical reports indicate attackers sent malicious emails to employees. One click opened the door.
Qilin ransomware detonates
Systems at the ACI Logistics head office in Tejgaon are locked. A ransom of USD 1.5 million is demanded.
The customer data is exfiltrated
Shwapno refuses to pay. The attackers walk out with the database.
Customers whose data was already stolen were never told — so they could not change passwords, brace for scam calls, or protect themselves. The company later said its technical team had assured management the data was recovered.
The dump goes public
Independent analyses report 400GB+ of records surfacing on the dark web — names, phone numbers, purchase histories.
A police report is finally filed
The company lodges a general diary — seven months after the attack — after learning the data had leaked.
The real cost isn't the ransom — it's losing control
Refusing the ransom was arguably the right call; you cannot trust a criminal's promise to delete anything. But it does nothing to undo the exposure. The moment attackers copied the database, Shwapno lost control of that data permanently. Names, numbers, and purchase histories are the raw material for targeted phishing, SIM-swap fraud, and impersonation — and once four million records are on the dark web, they are there for years, to be resold and recombined.
A pattern across Bangladesh
50M citizens exposed
A government website leaked names, addresses, phone numbers, and national ID numbers — found by an external researcher, not internal auditors.
City Bank breach
Client financial statements were exposed, pointing to weaknesses in session management and multi-factor authentication.
Titas Gas firewall
A report indicated root access to the firewall was sold on the dark web, despite assurances the servers were secure.
These are leadership problems, not tech problems
Security is owned by IT, not the board
Framed as a technical chore, it competes with — and loses to — everything else on the P&L.
"Recovery" is confused with "resolution"
Restoring systems is treated as the end of the incident, while exfiltrated data remains an ongoing crisis.
No disclosure plan exists
Without a rehearsed plan, the default response to a breach is delay and silence — the two worst reactions.
The regulatory stick is still soft
As the framework matures from CSA 2023 to the Cyber Security Ordinance 2025, prevention still feels optional where penalties feel distant.
How ceKapsys extends enterprise-grade security into the middle space
The hardest-hit companies aren't the tiny ones or the giants — they're the mid-market operators large enough to be a target but without a standing security team. ceKapsys packages the enterprise playbook into programs sized for the whole spectrum. Pick a size to see what that looks like.
Security essentials that actually get used
Small teams get breached through the same front door as everyone else — email. We start where the risk is highest and the lift is lowest.
- Bengali-first phishing simulation (Faand)
- MFA rollout across critical accounts
- Email filtering & basic hardening
- A one-page breach-readiness playbook
Enterprise-grade defense, without the enterprise headcount
This is the gap the Shwapno story exposes: companies large enough to be a target, but without a full security team. ceKapsys packages the enterprise playbook into a program a mid-market operator can actually run.
- Recurring Faand phishing campaigns + awareness training
- Security posture audit against real attack paths
- Layered controls: endpoint, segmentation, monitoring
- A tested incident-response & disclosure playbook
- Compliance alignment (incl. medico / DGDA-aware)
- Board-ready reporting in plain language
A standing defense, continuously pressure-tested
For organisations holding millions of records, single-point defenses are not enough. We run the offense against you before someone else does.
- Continuous phishing simulation & red-team exercises
- Deep audits + dark-web exposure monitoring
- SOC-style monitoring & response guidance
- Incident-response retainer with defined SLAs
- Regulatory & data-protection posture reviews
- Executive & board crisis-readiness drills
Close the gaps attackers actually use
Frequently asked
Reporting and independent analyses indicate attackers gained initial access through a phishing campaign aimed at employees, then deployed Qilin ransomware and exfiltrated the customer database. The intrusion began on 19 August 2025.
Shwapno holds records for roughly 40 lakh (4 million) registered customers. Reporting indicates names, phone numbers, and purchase histories were among the exposed data.
No. The attackers demanded USD 1.5 million and the company refused. The stolen data later surfaced publicly in March 2026.
Prioritise phishing-awareness training and simulations, enforce multi-factor authentication, build layered defenses, run independent security audits, and prepare a tested incident-response and breach-disclosure plan.
Don't wait for the leak to introduce you to your own risk.
ceKapsys helps organisations across Bangladesh — from mid-market to enterprise — find the open doors before attackers do, and stay ready when it counts.
Sources
- The Business Standard — reporting on the Shwapno breach and the general diary filed seven months later
- The Daily Star — Shwapno database breach coverage; Cybersecurity in Bangladesh 2025
- Bangladesh Monitor — scale of the exposure and phone-number lookup
- UpGuard — breach overview and risk analysis
- New Age — Guarding against data breach (Titas Gas, national data)
All figures and events describing the Shwapno / ACI Logistics incident are drawn from public reporting and independent analyses; the 400GB+ figure and the phishing entry vector reflect independent analyses rather than company confirmation. The company has stated it retained control of its own systems. This article is provided for security-awareness purposes.