feature Trade

$1.5m Ransom Sought in Shwapno Cyberattack

Customer data breach raises concerns over security and delayed disclosure

Written by The Banking Post


One of Bangladesh’s largest retail chains, Shwapno, has confirmed a major cyberattack in which hackers breached its customer database and demanded a $1.5 million ransom.

The breach surfaced after sensitive customer data—including names, phone numbers and purchase histories—began circulating on social media, sparking widespread concern.

Breach traced months back

Company officials said the attackers gained unauthorised access months earlier, with indications the intrusion dates back to late 2025. The ransom demand was reportedly issued in August last year.

Managing Director Sabbir Hasan Nasir said the company refused to pay, calling the demand “illegal and unethical” and reaffirming its policy against complying with cybercriminals.

Nationwide impact

A subsidiary of ACI Limited, Shwapno operates over 800 outlets across 63 districts and serves more than 4 million registered customers—highlighting the масштаб of the breach.

The company said no sensitive financial information was compromised.

Security measures tightened

Following the attack, Shwapno launched an internal audit and strengthened its cybersecurity infrastructure, including advanced firewalls, enterprise-grade server protection and 24/7 monitoring by local and international experts.

It is also working with the Counter Terrorism and Transnational Crime unit and forensic specialists to investigate the incident. A case is being processed in Tejgaon Industrial Area.

Concerns over delay, misuse risk

Despite these steps, concerns persist over the delay in informing customers, as the breach appears to have occurred months before disclosure.

Cybersecurity experts warn that leaked data—especially phone numbers and purchase histories—could be used for phishing and fraud.

Customers have been advised to remain cautious, avoid sharing personal information through unsolicited calls or messages, and steer clear of suspicious links.

The company has urged users to stay alert, reiterating that it never requests passwords or one-time codes over phone calls.


About the author