Chittagong Education Board: Personal data of 1 Million students leaked

Graphics: Agamir Somoy
Personal data of examinees under the Board of Intermediate and Secondary Education—including roll and registration numbers—is supposed to remain restricted to three official government servers. However, over the past four years in Chittagong, sensitive data of more than one million SSC and HSC students, including roll numbers, registration numbers, GPAs, and dates of birth, has become accessible on various private websites.
This compromise exposes a vast number of students to severe cyber risks and constitutes a violation of personal data protection laws. Because a significant portion of the victims are minors, exposing their information publicly without parental consent raises major concerns about cyber threats and social fraud. However, the education board authorities continue to brush off these security concerns.
An investigation by Agamir Somoy uncovered at least three such website domains. Two are hosted on vercel.app and one on github.io. On one of these sites, 14 types of data are directly visible, including roll and registration numbers, institution names, exam year, category, group, merit rank, total marks, GPA, parents' names, date of birth, and subject-wise scores. Complete details of SSC and HSC candidates from 2023, 2024, and 2026 are accessible here.
On a second site, anyone can view seven types of details, including student names, institution names, roll numbers, and GPAs. This platform exposes information across eight categories spanning SSC 2022, SSC and HSC from 2023 to 2025, and SSC 2026. Similarly, the third website publicly displays at least eight types of personal details, covering results for HSC 2024–2025 and SSC 2025–2026.
Experts emphasize that such sensitive data could not have been exposed unless the education board's official database was compromised or hacked.
According to official statistics, 722,399 students sat for the SSC exams under the Chittagong Board between 2023 and 2026, while 310,136 students took the HSC exams from 2023 to 2025. In total, personal and institutional data belonging to 1,032,535 candidates across these two public examinations has been leaked.
A random sample of 100 students' roll and registration numbers was cross-checked against the official education board result portal. While the government portal returns 11 data fields, the unauthorized websites display three additional sensitive data points for the same credentials, including exact dates of birth.
Under the Personal Data Protection Act 2026 and internationally recognized data privacy guidelines, information such as names, dates of birth, parents' names, and institutional IDs qualify as Personally Identifiable Information (PII). Publishing or displaying such data without explicit consent is illegal.
Parental Consent Ignored and Cyber Security Experts Sound the Alarm
Since the majority of secondary and higher secondary students are under the age of 18, relevant laws make it mandatory to obtain explicit parental consent before collecting or publishing their personal information. However, these unauthorized websites operate without any protective safeguards or consent protocols.
Speaking with Agamir Somoy, several cybersecurity analysts suggested that this data was likely breached from an internal database or API (Application Programming Interface) belonging to the Intermediate and Secondary Education Board. With names, institutional details, and parents' names publicly exposed, hackers and fraudsters can easily commit identity theft. Furthermore, commercial entities and coaching centers can exploit detailed marks and result data to target students with unsolicited contact, significantly escalating the risk of cyberbullying and harassment.
Mir Mu. Sakib Kawsar, Assistant Professor at Chittagong University of Engineering and Technology (CUET), highlighted the severity of the leak: "Accessing details on third-party websites that were never officially published by the board confirms a database breach. Web scraping would only harvest publicly visible data, not extra fields. This is a severe incident. Exposing personal details in the public domain leaves students vulnerable to fraud and various security risks. The education board bears full responsibility for safeguarding student data and must be held accountable."
He emphasized that government cybersecurity agencies and the education board must immediately take down these unauthorized websites and re-evaluate the board's database security infrastructure.
Miraj Ahmed Chowdhury, Managing Director of the digital rights and cybersecurity research organization Digitally Right, also expressed deep concern: "This is an extremely serious matter that places the security of the board’s entire digital infrastructure under scrutiny. Beyond violating data privacy laws, scammers can use this information to harass students and parents or target them with financial fraud. The education board must be brought to account."
However, Professor Dr. Parvez Sazzad Chowdhury, Controller of Examinations at the Chittagong Education Board, denied any direct leak from their system. He claimed: "No personal data has been exposed by the board, nor has anyone been authorized to do so. There is no scope for our primary database to be hacked. We share data with BUET, Chittagong Dockyard Limited, and Teletalk for result processing—it might have originated from those channels." He added that he does not believe this poses any significant risk.


