News

Ghorer Bazar Data Breach: 6 Lakh Customer Profiles Reportedly for Sale on Dark Web

Ghorer Bazar Data Breach

More than 42 lakh records allegedly linked to Bangladeshi e-commerce platform Ghorer Bazar have reportedly been put up for sale on a dark web forum.

The alleged database includes more than 6 lakh customer profiles, delivery addresses, order information and logistics records. Dark Web Intelligence highlighted the listing on September 13, 2026.

However, one important detail remains: Ghorer Bazar has not confirmed the breach. The company reportedly said its IT and investigation teams were reviewing customer complaints and had not found evidence confirming the claim.

That makes this an alleged data breach for now, rather than a confirmed cyberattack.

What Is the Ghorer Bazar Data Leak Claim?

According to the reported dark web listing, a threat actor is offering a 4.15GB production database allegedly taken from Ghorer Bazar on August 23.

The seller claims the database contains 311 tables and more than 42 lakh records.

The reported figures include:

  • 606,214 customer profiles
  • 372,615 delivery addresses
  • More than 449,000 orders
  • Around 862,000 individual items
  • Nearly 19.7 lakh delivery and logistics records
  • Alleged ERP and accounting information
  • Logs from an AI-powered customer support system

The seller reportedly offered access to the database for $1,000.

These numbers come from the threat actor’s claim and should not be treated as independently verified figures.

A Sample of 1,000 Records Was Reportedly Reviewed

The claim received more attention after New Age reported that it reviewed a sample of 1,000 records posted by the seller.

According to the newspaper, the sample appeared consistent with Ghorer Bazar’s customer and operational data.

That does not prove that the entire database is genuine.

It also does not establish how the information was obtained, when unauthorised access may have happened, or whether all of the claimed records came directly from Ghorer Bazar.

This distinction matters because stolen-data sellers sometimes exaggerate the size or value of datasets to attract buyers.

Ghorer Bazar Has Not Confirmed the Breach

Ghorer Bazar’s response is one of the most important parts of this story.

The company’s sales and customer experience executive, Mohammed Sakib, reportedly said the IT and investigation teams were reviewing customer complaints.

He said the company had not found evidence confirming the claim at that point.

So far, no publicly confirmed information establishes the attack method, the identity of the threat actor, or the exact number of affected customers.

This is similar to another type of dark web alert we recently covered involving ValueFirst, where a company appeared in a dark web intelligence post but no confirmed breach had been established.

The key difference is that the Ghorer Bazar claim includes a much larger alleged dataset and a reported sample of records.

Why the Customer Data Could Matter

Ghorer Bazar is an online food and grocery platform operating in Bangladesh. Its public app information shows that the service handles information such as names, phone numbers, physical addresses, purchase history and payment-related information as part of its operations.

If the alleged database is genuine, exposed customer profiles could create risks beyond simple spam.

For example, criminals could use names, phone numbers, delivery addresses and order information to create more convincing phishing and social-engineering scams.

A scammer who knows what someone ordered or where an order was delivered may be able to make a fake delivery call or message look much more believable.

If account credentials were also exposed, the risk could be higher, especially for people who reuse passwords on other websites.

The U.S. Cybersecurity and Infrastructure Security Agency recommends multifactor authentication because it adds another layer of protection when passwords are compromised.

The AI Customer Support Data Raises Another Question

One of the more unusual claims is that the database allegedly contains logs from Ghorer Bazar’s AI-powered customer support system.

If that part of the listing is authentic, the exposure could involve information customers shared while asking for help.

Customer support conversations can include order numbers, delivery details, contact information, and other details users may not expect to appear outside the company’s systems.

It is still too early to say whether those logs are genuine or how much information they contain.

What Should Ghorer Bazar Customers Do?

Customers do not need to assume that their information has definitely been leaked.

But anyone who has used Ghorer Bazar should be more careful with unexpected messages involving orders, refunds, deliveries or account verification.

Watch for:

  • Fake delivery calls or SMS messages
  • Unexpected password-reset emails
  • Messages asking for OTPs or account details
  • Suspicious refund offers
  • Links claiming to track a Ghorer Bazar order
  • Unusual login alerts

Do not share an OTP or password simply because the caller knows your name, phone number or previous order details.

If you reused your Ghorer Bazar password on another service, changing that password is also a sensible precaution.

Our guide on what to do if your information is on the dark web explains the practical steps people can take after their personal data appears in a leaked dataset.

Bangladesh’s E-Commerce Sector Faces a Growing Data Security Challenge

The reported Ghorer Bazar incident also highlights a wider issue for Bangladesh’s growing online shopping market.

E-commerce platforms hold large amounts of customer information, including contact details, delivery addresses and purchase records.

Bangladesh’s official cyber-security resources already recognise data protection and e-commerce security as important areas. BGD e-GOV CIRT, the country’s national computer incident response team, provides services including incident response, digital forensics and cyber threat intelligence.

Bangladesh’s e-commerce policy also requires customer information such as names, email addresses, mobile numbers, and delivery addresses to be kept confidential and secure.

What Happens Next?

The most important question now is whether the alleged database can be independently verified.

Ghorer Bazar’s investigation could clarify whether its systems were compromised, what information may have been accessed and whether the dark web listing actually originated from the company.

For customers, the safest approach is to stay alert without assuming that every claim in the listing is true.

For cybersecurity researchers, the sample records and any future evidence could help establish whether the database is genuine, how recent it is and whether the seller’s claims about its size are accurate.

For now, the Ghorer Bazar data breach remains alleged. The reported sale of more than 6 lakh customer profiles is serious enough to watch, but the full scope and authenticity of the claimed database have not been publicly confirmed.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

📋 Latest Articles

View all →
Telegram Credential Leak Channels
Data Breaches

Top 5 Telegram Credential Leak Channels: How Stolen Logins Are Traded

Telegram is no longer just a messaging app for chatting and sharing files. Security researchers have found that…

Sep 18, 2026
5 min read
Gabbie Gonzalez Pleads Not Guilty in Dark Web Murder Plot Against Jack Avery
News

Gabbie Gonzalez Pleads Not Guilty in Dark Web Murder Plot Against Jack Avery

TikTok influencer Gabbie Gonzalez, her father Francisco Gonzalez, and her ex-boyfriend Kai Cordrey all pleaded not guilty on…

Sep 17, 2026
7 min read
Dark Web Intelligence Market
News

The Dark Web Intelligence Market Is Growing at 21% Per Year. Here’s Why.

The dark web intelligence market, estimated at $0.92 billion in 2026 by The Business Research Company, is projected…

Sep 16, 2026
11 min read
South Korea Is Building a 700-Billion-Parameter AI Trained on Dark Web Data
News

South Korea Is Building a 700-Billion-Parameter AI Trained on Dark Web Data. Here’s Why That’s a Big Deal.

South Korea’s Ministry of Science and ICT has selected a 33-organisation consortium, led by Naver Cloud, to develop…

Sep 15, 2026
11 min read
dark web hitman site
News

She Paid $1,400 on a Dark Web Hitman Site to Have Her Ex-Husband Killed. He’s Alive. She’s Under Arrest.

A 45-year-old woman was arrested in Rotterdam on September 12, 2026, suspected of involvement in ordering a contract…

Sep 15, 2026
11 min read
Twitch Data Leak: 40,000 Streamers Had Data Listed for Sale. A Browser Extension Was the Likely Culprit.
News

Twitch Data Leak: 40,000 Streamers Had Data Listed for Sale. A Browser Extension Was the Likely Culprit.

On September 9, 2026, a threat actor listed a database of approximately 40,000 Twitch streamer records for sale…

Sep 15, 2026
10 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted