Wed, 26 August 2026
The Daily Ittefaq

CVs for Sale

Update : 25 Aug 2026, 09:56

Recently, concern and anxiety have arisen over advertisements on the dark web offering for sale the résumés of a large number of Bangladeshi job seekers.

A hacker group identifying itself as “Madarox” has claimed to possess the CVs of nearly six million users of Bdjobs, one of Bangladesh’s most popular job websites.

Although Bdjobs authorities have categorically denied the claim, the publication of 148 sample CVs and the advertisement offering the data for sale warrant a proper investigation. This cannot simply be treated as an ordinary cybersecurity incident.

The matter is particularly sensitive because a job seeker’s résumé contains much more than just a name or mobile phone number.

It may include an address, email address, educational qualifications, employment history, training records, and various other important details about the person’s personal and professional life.

By bringing all this information together, it is quite easy to create a comprehensive digital identity of an individual. Therefore, if such information falls into the hands of unauthorized parties, the risks of targeted phishing, fake job offers, identity fraud, and financial scams can increase many times over.

The European Data Protection Board (EDPB) itself has identified identity theft, fraud, and financial loss as among the possible consequences of personal data breaches.

It is worth noting that the EDPB is an independent body of the European Union (EU) responsible for ensuring the consistent application of the General Data Protection Regulation (GDPR) and data-protection rules across Europe.

The biggest reason for concern is that if this information has indeed fallen into the hands of an unauthorized party, it is only natural to ask: how did this happen? And if the claim is not true, then what is the source of the published samples?

Therefore, simply denying the claim cannot be considered the end of the matter. An independent investigation, technical verification, and, where necessary, assistance to affected individuals are also urgently needed.

In the age of information technology, the unauthorized disclosure of data in this manner cannot be accepted under any circumstances. Surely, the relevant authorities will properly oversee the matter and take appropriate action.

What do we see in the developed world? There, the security of personal information is not regarded merely as an internal matter for an organization. Under the EU’s GDPR, when a data breach poses a risk to individuals, the relevant authorities generally must be notified within 72 hours; where there is a high risk, the affected individuals must also be informed.

The U.S. National Institute of Standards and Technology (NIST) likewise places particular emphasis on preparedness, rapid detection, response, and recovery in dealing with data breaches.

So why should we not also develop a culture in which personal information is regarded as an “asset” and its security as a “responsibility”?

Whenever citizens’ information is collected by job websites, banks, hospitals, educational institutions, or any public or private digital platform, the responsibility for protecting that information also rests with the organization concerned. Having only passwords and firewalls is not enough to discharge that responsibility.

Regular security assessments, verification of whether data collection is necessary, restricted access to databases, encryption, monitoring, and rapid action following a data breach—all of these measures must be ensured.

We must remember that we live in an age when “information is power.” At such a time, if people’s personal information is not secure, that very power can turn into a source of danger for them.

In other words, a data breach should not be regarded as merely a technical error; rather, it should be considered a direct threat to people’s personal security, dignity, and future.

If, because of an organization’s negligence, inadequate security measures, or carelessness, citizens’ personal information falls into the hands of criminals, there should be no scope for that organization to evade responsibility.

At the same time, such organizations must exercise due caution and adopt appropriate security measures when collecting citizens’ information.

After all, while collecting citizens’ data may be easy, ensuring the security of that information carries an equally—and perhaps even more—serious responsibility.

More on this topic

More on this topic