Dectrax
[PRESS RELEASE]

Top 10 Cybersecurity Attacks That Shaped Bangladesh (2016–2026)

February 8, 2026By Albert Griffin
Top 10 Cybersecurity Attacks That Shaped Bangladesh (2016–2026)

As Bangladesh moves toward a fully digitized economy, the landscape of risk has shifted from isolated banking incidents to systemic infrastructure vulnerabilities. In February 2026, marking the 10-year anniversary of the infamous central bank heist, the nation reflects on the most significant breaches that have forced a total overhaul of digital defense strategies.

1. The Bangladesh Bank "Cyber Heist" (2016)

Still the world's most cited financial cyber-incident, hackers linked to the Lazarus Group compromised the central bank's SWIFT credentials to attempt a $951 million theft from the Federal Reserve Bank of New York. While most was blocked, $81 million was laundered through casinos in the Philippines.

  • Legacy: Prompted a global shift in how interbank payment security is managed.

2. The Great Government Data Leak (2023)

A critical vulnerability in the Office of the Registrar General, Birth and Death Registration website exposed the sensitive personal data of over 50 million citizens.

  • Details: Names, NID numbers, and addresses were accessible via a simple Google search, highlighting severe infrastructure weaknesses.

3. Coordinated "DDoS Storm" on 25 Institutions (2024)

A surge in cyberattacks (up 105%) saw a coordinated DDoS (Distributed Denial of Service) strike targeting 25 major public and private entities, including the Directorate General of Health Services (DGHS).

4. Election Commission (EC) Data Exposure (2025-2026)

Approaching the 2026 elections, the EC faced multiple incidents where voter and journalist data (over 14,000 records) were unintentionally exposed through its digital platforms.

5. Titas Gas "Root Access" Sale (2024)

In a daring move, hackers offered full "root access" to the internal systems of Titas Gas for sale on the dark web, threatening critical energy infrastructure.

6. RansomHub Strike on Bangladeshi Tech Giant (2024)

Global ransomware group RansomHub successfully breached a major domestic technology firm, marking a new era where local enterprises are targeted by professional international extortion rings.

7. Army Cantonment Database Breach Allegations (2024)

Investigators launched an intensive probe into a suspected breach of military-related databases, raising national security concerns regarding the integrity of personnel records.

8. DESCO Customer Data Breach (2024)

The Dhaka Electric Supply Company (DESCO) suffered an exfiltration of customer records, exposing thousands of households to targeted phishing and social engineering risks.

9. Bangladesh Railway E-Ticketing Blackout (2023)

A high-traffic DDoS attack rendered the national rail ticketing system unavailable for several hours, demonstrating the impact of "service-denial" on public infrastructure.

10. AI-Driven "Deepfake" Financial Fraud (2026)

In early 2026, the rise of AI-enabled phishing saw the first wave of successful deepfake audio attacks targeting corporate leadership for unauthorized wire transfers, marking the newest frontier of cybercrime.

The DentiSystems Perspective

These incidents reveal a persistent pattern: technical debt and unpatched vulnerabilities.

  • Democratizing Defense: While heists target the top, breaches like the 2023 leak harm everyone. Our DarkCheck and LeakScan tools are provided for free so any citizen or small business can verify their exposure.
  • Cyber Immunity: DentiSystems is currently developing DentiGrid, an autonomous AI Defense Grid designed to neutralize the types of DDoS storms and AI-driven malware seen in this list.
  • Precision Auditing: With our VAPT (Vulnerability Assessment and Penetration Testing) services starting as low as $29–$49, we ensure that "important information infrastructure" organizations can close gaps before they become the next headline.
Albert Griffin

AUTHOR

Albert Griffin

Security Communications, Dectrax