A disturbing claim about the personal information of millions of Bangladeshi job seekers has raised fresh concerns over online privacy and cybersecurity. A hacker group calling itself “MadRax” allegedly claims to possess around 6 million CVs belonging to job seekers registered with popular employment website Bdjobs.
According to the claim, the alleged database has been advertised for sale on a dark web forum. The sellers reportedly published samples of 148 CVs as evidence and are asking potential buyers to pay for access to the information.
If the claim is genuine, the incident could expose millions of job seekers to targeted scams, phishing attempts, identity fraud and other forms of cybercrime. A typical CV contains much more than professional information. It can include a person’s full name, phone number, email address, home address, educational background, employment history and training details.
However, there is an important point to keep in mind: Bdjobs has denied that the information was stolen directly from its database. Therefore, the hacker group’s claim has not, by itself, established that Bdjobs suffered a data breach.
Hacker Group Claims 6 Million CVs Are Available
The alleged advertisement reportedly appeared on a website known as DarkForums.ru. In the post, the group identifying itself as MadRax claimed to have obtained approximately 6 million CVs associated with Bdjobs users.
The alleged database reportedly contains a wide range of personal and professional information. This includes names, telephone numbers, email addresses, residential details, educational qualifications, employment records and training information.
The group reportedly offered a copy of the alleged data to interested buyers for $1,000. The advertisement also claimed that the same information would be sold to no more than five buyers.
Several payment methods were reportedly mentioned, including online financial services and cryptocurrency. Such details are common in underground data-selling operations, although the presence of a sales advertisement does not prove that the seller actually possesses the amount or quality of information being advertised.
That distinction is important because cybercriminals sometimes use old, publicly available or previously leaked information to create convincing-looking advertisements.
148 CV Samples Published as Alleged Proof
To support its claims, the hacker group reportedly released 148 CV samples.
The publication of these documents attracted attention because the samples appeared to contain genuine personal and professional information. However, reports indicated that many of the CVs were several years old, with a significant number last updated between 2011 and 2017.
Old information may not appear dangerous at first glance, but it can still have value to cybercriminals.
For example, an old phone number, email address, workplace or educational record can be combined with newer information found elsewhere online. When several pieces of information are connected, criminals can build a more detailed profile of an individual.
Two people whose CVs were reportedly among the published samples were contacted for comment. Both were employed by private companies and said they had uploaded their CVs to Bdjobs several years ago.
Their accounts may indicate that at least some of the documents relate to real Bdjobs users. However, that still does not prove how the hacker group obtained the files or whether they came directly from Bdjobs’ systems.
Why a Leaked CV Can Become a Cybersecurity Threat
A CV may not contain a bank account password or credit card number, but that does not mean it is harmless.
The real danger comes from combining multiple pieces of information. A person’s name, phone number, email address, address, educational background and employment history can collectively create a detailed digital profile.
Cybercriminals can use such profiles to make scams appear far more convincing.
Imagine that a scammer knows a job seeker’s name, previous employer and phone number. The scammer could call the person and pretend to represent a recruitment company. Because the caller already knows genuine details about the victim’s career, the conversation may appear legitimate.
The scammer might then claim that the person has been selected for a job and needs to pay a registration fee, training charge or processing cost.
This type of targeted deception can be much more effective than a random scam message because the criminal already knows something about the victim.
Phishing and Fake Job Offers Could Become a Major Risk
Email-based scams are another potential concern.
A criminal could use information from a CV to create a fake recruitment email that appears to be tailored specifically to the recipient. Mentioning the person’s educational qualifications, previous employer, or job experience could make the message seem authentic.
The email might contain a malicious attachment or a link leading to a fake recruitment website.
The victim could then be asked to enter a password, provide banking information or upload additional documents.
This makes leaked employment data particularly useful for targeted phishing attacks. Instead of sending the same message to thousands of random people, criminals can create personalised messages based on information already associated with each target.
Identity Fraud and Financial Scams Are Also Possible
Another concern is identity-related fraud.
When criminals obtain someone’s professional and personal information, they may attempt to impersonate that person or use the information as part of a larger identity-fraud operation.
Cybersecurity experts have warned that combining several pieces of personal information can allow criminals to construct detailed digital profiles.
Those profiles could potentially be used for targeted phishing, fake employment offers, impersonation attempts and financial scams.
The age of the information does not necessarily eliminate the risk. Even if someone uploaded a CV more than a decade ago, parts of the information may still be accurate today.
An old educational record, a former employer, or a professional qualification can also be used to make a fraudulent message appear credible.
Bdjobs Denies Its Database Was Stolen
The hacker group’s advertisement reportedly suggested that the information came from Bdjobs. The company, however, has rejected that claim.
Bdjobs founder and chief executive Fahim Mashroor has said the company has always treated user data security as a priority. The platform has security measures in place and controls over who can access job seekers’ profiles.
Recruiting companies registered with Bdjobs can access candidate information through their accounts for hiring purposes. However, that access is intended for recruitment activities.
According to Mashroor, if a recruiting company is found to have sold job seekers’ information to a third party and evidence is provided to Bdjobs, legal action can be considered against the company involved.
This response highlights an important issue in the case: information appearing on a dark web marketplace does not automatically mean that the original platform was hacked.
Does the Dark Web Advertisement Prove a Data Breach?
Not necessarily.
A dark web advertisement is an allegation, not independent proof of where the information came from.
Cybercriminals can collect data from many different sources. They may use previously leaked databases, information gathered from public websites, old breaches or data obtained from third parties.
In some cases, criminals may also exaggerate the size or quality of a dataset to attract buyers.
That is why cybersecurity investigators would need to examine the alleged CVs carefully. They would need to determine when the information was created, where it originally appeared and whether the records match historical or current Bdjobs databases.
Investigators would also need to establish whether the information was obtained through a security breach, unauthorised access, an insider source or another channel.
Until such technical verification takes place, the claim that 6 million Bdjobs CVs were stolen should be treated as an allegation rather than a confirmed breach.
What Job Seekers Should Do Now
People who have used online job portals should not panic, but they should remain alert.
Be especially careful if an unknown person contacts you about a job and already knows details from your CV. Having genuine personal information does not prove that the caller represents a legitimate employer.
Never send money simply because someone claims you have been selected for a job. Legitimate recruitment processes should be independently verified before making payments or sharing sensitive information.
Job seekers should also be cautious with emails and messages that contain unexpected links or attachments. Even if the sender uses a familiar company’s name, check the email address and verify the recruitment opportunity on the company’s official website or through known contact channels.
Most importantly, never share passwords, one-time passwords or sensitive banking information with someone claiming to be a recruiter.
Using different passwords for different online accounts is also strongly recommended. Two-factor authentication should be enabled wherever possible, particularly for email accounts and other important services.
A Wider Warning About Personal Data Protection
Whether the 6-million-CV claim is ultimately proven or disproved, the incident highlights a larger problem: personal information has become valuable to cybercriminals.
Job seekers routinely upload detailed information to employment websites to help recruiters find them. That makes these platforms useful, but it also means users are trusting companies to store and protect large amounts of personal data.
The more information a database contains, the more attractive it can become as a potential target.
For users, the lesson is simple. Sharing a CV online may be necessary when looking for work, but people should understand what information they are providing and avoid including unnecessary sensitive details.
For companies, protecting user information must remain a priority. Strong security controls, access management, monitoring and rapid responses to suspected breaches can help reduce the potential damage from cyberattacks.
The alleged sale of millions of Bangladeshi CVs on the dark web is therefore more than just a disturbing cybercrime story. It is a reminder that personal information can remain useful to criminals long after it is originally shared.
Until the source of the alleged data is independently established, the claims surrounding the 6 million CVs should be treated with caution. At the same time, job seekers can take simple precautions now to reduce their exposure to phishing, fake recruitment scams and identity fraud.

