Barcelona · Product & Engineering

Sakib Bin Kamal

I build software that can't misuse your data — not software that promises it won't. I write about the difference.

ΛΟΓΟΙEssay

The Going Rate

My NID number, my phone number, my parents' names are for sale for a few hundred taka. So are yours. What changed in how I live after spending a month reading a decade of Bangladeshi data breaches.

Barcelona · 9 August 2026

5 min read

Somewhere on a ransomware leak portal is a 410 GB folder taken from Bangladesh's biggest supermarket chain: four million customers' names and phone numbers, and about 270 million records of what they bought, keyed to those numbers.

I don't know whether my family is in it. Neither do you, about yours. That's the detail I can't leave alone — not the breach itself, the silence. The company knew for seven months before the data went public, and in those seven months nobody was told to expect the fraud calls that data makes possible. People found out from Facebook.

A few weeks after that leak, the final voter roll from February's election went on sale — also on Facebook, some of it through paid ads. Tk 250 for the whole country: names, voter numbers, parents' names, dates of birth, addresses. Constituency slices for Tk 30. On Telegram, free.

Two hundred and fifty taka is about two US dollars.

I spent the past weeks reading everything public about a decade of this. The 2016 central bank heist. The 2023 government portal that exposed fifty million birth records — found by a researcher who was Googling an SQL error message, and left up for two weeks while his six warning emails went unanswered. The Telegram bot that returned anyone's NID details from a ten-digit number. The Election Commission insiders who sold 365,000 records in a single month with their own logins.

The full investigation, with every incident sourced and what it means for the law and for you, is on Dooplin: Two Hundred and Fifty Taka, also published in বাংলা. This page is the short, personal version: what actually changed in how I live after writing it.

The one idea that stuck

Every field this country uses to prove I am me — NID number, phone number, parents' names, date of birth, permanent address — is now merchandise. Not “might be exposed someday.” Is, today, for a few hundred taka.

But every verification flow I meet still treats those fields as secrets. The bank agent asks for my NID digits. The delivery man reads my address back to me as proof he's legitimate. A caller who knows my mother's name expects that to open the conversation. The entire system runs on a knowledge test whose answer key is publicly for sale.

Once you see that, you can't unsee it. Knowledge is dead as proof of identity in Bangladesh. Whoever demands it, whoever offers it — it proves nothing.

What I do differently now

Not advice, exactly. Just what I've changed.

  1. I treat my NID number like my name, not my password. It identifies me; it does not authenticate me. I've stopped being impressed when a stranger on the phone knows it.
  2. Inbound calls get nothing.If my “bank” calls, I hang up and call the number on my card. Every time, no exceptions, even when it's inconvenient — especially when the caller is manufacturing urgency, because urgency is the tell.
  3. My email got the best lock first. Unique password, two-factor, authenticator app rather than SMS. Every “forgot password” flow on every service I use terminates in that inbox; it's the master key, so it gets the strongest protection.
  4. Transaction alerts, on, and actually read. Detection at my end is the only control I fully own.
  5. NID photocopies get written on. Purpose and date, across the copy, before it leaves my hand. The blank look I get when I ask what happens to it afterwards has been an education in itself.

And because I build software

I can't only think about this as a customer. The systems in that decade of failures were built by people like me, and almost none of the failures were sophisticated: an API that never checked who was asking, access logs nobody read, data kept forever because deletion had no owner, a security inbox that didn't exist.

So there are questions I now ask about anything I ship or touch, and they're embarrassingly basic. Does this endpoint check authorisation, or just login? Who reads the access logs, and how soon? When does this data get deleted, and who owns making that true? If a stranger found a hole tomorrow, would they have any way to tell us?

That last one is a text file. It took ten minutes, and I put off writing it for longer than I would like to admit.

The price

The market has already set the price of our data: two dollars for everyone in the country. That price is an exact measurement of how much protecting it has cost the institutions that hold it — which is to say, nothing.

Prices move when costs move. Breach notification with teeth, penalties that scale with the number of people harmed, a CERT that answers its email, and a few million citizens who have stopped accepting an NID number as proof of anything — that's what raises it.

Until then, I'm adjusting to living at the going rate. I'd rather we raised it.

← All writing

The full investigation: dooplin.com