rdcd.gov.bd data breach

rdcd.gov.bd

What Happened

In March 2026, a data breach targeted the Rural Development and Co-operatives Division (RDCD) of the Bangladesh government, associated with the rdcd.gov.bd domain, when threat actor “Lei$” announced the leak of a 700MB–1GB uncompressed database containing sensitive employee and HR data (including names and contact details), critical authentication files (such as session tokens, hashed credentials, or access keys), and user/citizen profiles from rural development and co-operative programs, organized across 5 CSV folders for easy exploitation. This exposure, described as a systemic security failure providing a “digital skeleton key” for lateral movement into government networks, emerged amid post-“Operation Alice” dark web disruptions, posing risks like social engineering, credential stuffing, identity theft, and disruption of local governance and aid distribution. No exact number of records was specified, but the data represents a functional blueprint of RDCD operations, prompting urgent recommendations for credential resets, FIDO2 MFA, and data loss prevention.

Compromised Assets

  • email
  • password
  • full name
  • phone
  • ip

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.

Related Breaches