Case study · Bangladesh

Their data was searchable by phone number.

Major companies in Bangladesh still treat cybersecurity as an afterthought. Four million Shwapno customers found out what that costs.

Qilin ransomware $1.5M ransom refused 7 months of silence
EXPOSED RECORD src: darkweb_dump/shwapno
Full name
MD ██████ H.
Mobile
+8801X-XXX-XX21
Last basket
Rice · cooking oil · diapers
Loyalty tier
Gold · 3y active
// Illustrative sample — not real customer data
4,000,000
Customer records exposed
800+
Outlets nationwide
63
Districts reached
$1.5M
Ransom demanded
7
Months before disclosure
410GB
Data reportedly leaked
The uncomfortable truth

Security is still an afterthought for large enterprises

For a decade, "Digital Bangladesh" pushed banking, retail, healthcare, and government services online at remarkable speed. Investment in the thing that keeps all that data safe did not keep pace. The warning signs were never subtle — a 2023 government exposure of an estimated 50 million citizens' data, a City Bank breach in early 2025, Titas Gas firewall access reportedly sold on the dark web.

The common thread is not sophistication on the attacker's side. It is complacency on the defender's side — security budgets cut first, incident-response plans that exist only on paper, and "we haven't been hacked yet" mistaken for a strategy. In 2026, Shwapno paid that bill in full.


Anatomy of the breach

The Shwapno (ACI Logistics) breach, step by step

Shwapno is not a small operation. A subsidiary of ACI Limited, it runs 800+ outlets across 63 districts and holds records for around 4 million customers. If any organisation had the resources to defend itself, it was this one. This is how it unfolded, reconstructed from reporting by The Business Standard, The Daily Star, and Bangladesh Monitor.

Before 19 Aug 2025

Reconnaissance & phishing

Analytical reports indicate attackers sent malicious emails to employees. One click opened the door.

19 Aug 2025 · ~2:00 PM

Qilin ransomware detonates

Systems at the ACI Logistics head office in Tejgaon are locked. A ransom of USD 1.5 million is demanded.

Aug 2025 → Mar 2026

The customer data is exfiltrated

Shwapno refuses to pay. The attackers walk out with the database.

◆ Seven months of silence
210+ days, no public warning

Customers whose data was already stolen were never told — so they could not change passwords, brace for scam calls, or protect themselves. The company later said its technical team had assured management the data was recovered.

March 2026

The dump goes public

Independent analyses report 400GB+ of records surfacing on the dark web — names, phone numbers, purchase histories.

28 Mar 2026

A police report is finally filed

The company lodges a general diary — seven months after the attack — after learning the data had leaked.

The real cost isn't the ransom — it's losing control

Refusing the ransom was arguably the right call; you cannot trust a criminal's promise to delete anything. But it does nothing to undo the exposure. The moment attackers copied the database, Shwapno lost control of that data permanently. Names, numbers, and purchase histories are the raw material for targeted phishing, SIM-swap fraud, and impersonation — and once four million records are on the dark web, they are there for years, to be resold and recombined.


Not an isolated case

A pattern across Bangladesh

2023

50M citizens exposed

A government website leaked names, addresses, phone numbers, and national ID numbers — found by an external researcher, not internal auditors.

Jan 2025

City Bank breach

Client financial statements were exposed, pointing to weaknesses in session management and multi-factor authentication.

Nov 2024

Titas Gas firewall

A report indicated root access to the firewall was sold on the dark web, despite assurances the servers were secure.

Why it keeps happening

These are leadership problems, not tech problems

A

Security is owned by IT, not the board

Framed as a technical chore, it competes with — and loses to — everything else on the P&L.

B

"Recovery" is confused with "resolution"

Restoring systems is treated as the end of the incident, while exfiltrated data remains an ongoing crisis.

C

No disclosure plan exists

Without a rehearsed plan, the default response to a breach is delay and silence — the two worst reactions.

D

The regulatory stick is still soft

As the framework matures from CSA 2023 to the Cyber Security Ordinance 2025, prevention still feels optional where penalties feel distant.

The way forward

How ceKapsys extends enterprise-grade security into the middle space

The hardest-hit companies aren't the tiny ones or the giants — they're the mid-market operators large enough to be a target but without a standing security team. ceKapsys packages the enterprise playbook into programs sized for the whole spectrum. Pick a size to see what that looks like.

The middle space · our focus

Enterprise-grade defense, without the enterprise headcount

This is the gap the Shwapno story exposes: companies large enough to be a target, but without a full security team. ceKapsys packages the enterprise playbook into a program a mid-market operator can actually run.

  • Recurring Faand phishing campaigns + awareness training
  • Security posture audit against real attack paths
  • Layered controls: endpoint, segmentation, monitoring
  • A tested incident-response & disclosure playbook
  • Compliance alignment (incl. medico / DGDA-aware)
  • Board-ready reporting in plain language
Bengali-firstAwareness training and phishing simulation built for how your team actually reads and works — not translated afterthoughts.
Compliance-awarePrograms that account for Bangladesh's regulatory environment, including medico and DGDA-sensitive contexts.
Readiness over theatreWe measure success by a tested response plan and a shrinking click-rate — not a dashboard nobody opens.
Do this before the leak

Close the gaps attackers actually use

Treat phishing as your #1 threat. The Shwapno intrusion started with an email. Run realistic phishing simulations and awareness training so people recognise the bait.
Enforce MFA everywhere. Stolen passwords are how most intrusions escalate. Multi-factor authentication blocks the majority of them.
Build defense in depth. Email filtering, endpoint protection, segmentation, and monitoring mean one mistake doesn't hand over the whole database.
Write — and rehearse — a disclosure plan. Deciding how you'll notify customers after a breach is already too late. Separate "system recovery" from "data exposure."
Get an independent assessment. Companies rarely spot their own blind spots. A third-party audit finds the open door before an attacker does.

Questions

Frequently asked

Reporting and independent analyses indicate attackers gained initial access through a phishing campaign aimed at employees, then deployed Qilin ransomware and exfiltrated the customer database. The intrusion began on 19 August 2025.

Shwapno holds records for roughly 40 lakh (4 million) registered customers. Reporting indicates names, phone numbers, and purchase histories were among the exposed data.

No. The attackers demanded USD 1.5 million and the company refused. The stolen data later surfaced publicly in March 2026.

Prioritise phishing-awareness training and simulations, enforce multi-factor authentication, build layered defenses, run independent security audits, and prepare a tested incident-response and breach-disclosure plan.

Don't wait for the leak to introduce you to your own risk.

ceKapsys helps organisations across Bangladesh — from mid-market to enterprise — find the open doors before attackers do, and stay ready when it counts.

Sources

  • The Business Standard — reporting on the Shwapno breach and the general diary filed seven months later
  • The Daily Star — Shwapno database breach coverage; Cybersecurity in Bangladesh 2025
  • Bangladesh Monitor — scale of the exposure and phone-number lookup
  • UpGuard — breach overview and risk analysis
  • New Age — Guarding against data breach (Titas Gas, national data)

All figures and events describing the Shwapno / ACI Logistics incident are drawn from public reporting and independent analyses; the 400GB+ figure and the phishing entry vector reflect independent analyses rather than company confirmation. The company has stated it retained control of its own systems. This article is provided for security-awareness purposes.