Tappware 2024 Data Breach

Tappware Employee Monitoring Platform Breach (2024): 95K User Records Exposed

Technology Services Company · Digital identity, e-KYC, and workflow software services · Identity verification and workflow platform · Global

Tappware Employee Monitoring Platform Breach (2024): 95K User Records Exposed

Technology company providing identity verification and workflow automation tools.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
95KRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
Gov IDGovernment ID
AddressPhysical address
Classification Tags
EmploymentJob SearchUsers2024

Breach Summary

Tappware, a Bangladeshi IT services and identity-verification platform, suffered a data breach on April 23, 2024 when an attacker exfiltrated approximately 34 to 50 gigabytes of data including approximately 2.3 million rows of personal information from Tappware's systems, with the breach data subsequently published on a hacking forum on May 1, 2024. The breach was discovered by the Bangladesh Cyber Security Intelligence (BCSI) during routine monitoring activities. Have I Been Pwned indexed the breach on May 9, 2024 with 94,734 unique email addresses extracted from the broader leak. The breach affected approximately 95,000 unique email addresses based on records indexed by Have I Been Pwned, with the broader 2.3 million-row dataset covering a substantially larger population of Bangladeshi citizens. Compromised fields included email addresses, full names, dates of birth, gender, religion, job titles, phone numbers, physical addresses, and scans of Bangladeshi national identity (NID) cards. The exposed dataset was structured across multiple files including employee records, profile records, trainee information, user accounts, and worker information files, indicating that Tappware's data covered both individual users and enterprise workforce records collected through identity-verification and worker-management workflows for client organizations. For affected individuals, the practical risk profile is exceptionally severe due to the inclusion of national identity card scans alongside the full identity profile. The combination of NID card scans, full name, date of birth, address, and phone number provides essentially a complete identity-fraud kit that supports impersonation across Bangladeshi banking, telecommunications, government services, and employment verification systems. The exposure of religious affiliation data creates additional risk of targeted harassment or discrimination in Bangladesh's communal context. Affected individuals should monitor their financial accounts, banking activity, and any identity-verification activity for unauthorized changes; remain alert to phishing or impersonation attempts referencing real personal details; and consider notifying Bangladeshi authorities if any unauthorized identity activity is detected. The persistence of NID-card data in the leaked dataset means the identity-fraud risk extends across an indefinite timeframe because Bangladeshi NID numbers do not change for an individual. The combination of employment data including job titles and employer information also creates risk of employment-based social engineering attacks targeting either the affected individuals or their employers.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

95K records analyzed

About Tappware

Tappware Solutions Limited is a Bangladeshi information-technology services and software-development company headquartered in Dhaka. The company provides identity verification, electronic Know Your Customer (e-KYC), workflow automation, and digital identity services to enterprise customers in Bangladesh including labor management, employment verification, and worker onboarding workflows. Tappware operates the tappware.com domain and provides software-as-a-service products that aggregate substantial personal-identification data including Bangladeshi national identity card (NID) information used for identity verification of workers and employment applicants. As an identity-verification service provider, Tappware maintains highly sensitive personal data on a substantial population of Bangladeshi citizens including identity scans, demographic profiles, employment records, religious affiliation data, and contact information.

Why They Hold Your Data

Identity-verification and workflow platforms collect customer identity, e-KYC records, document data, workflow activity, and account-management information across verification and business-process services.

Recent Developments

The breach was discovered by the Bangladesh Cyber Security Intelligence (BCSI) during routine monitoring activities on cybercriminal trading platforms, with BCSI publicly disclosing the incident on May 12, 2024. Bangladesh BCSI recommended that Tappware activate an incident response plan, conduct comprehensive security audits, implement multi-factor authentication, and enhance employee cybersecurity training. The breach was indexed by Have I Been Pwned on May 9, 2024. The case sits within a broader pattern of substantial Bangladeshi personal-data exposures during 2023-2024 including the Bangladeshi government NID server leak that exposed personal information of approximately 50 million Bangladeshi citizens (a separate incident from the Tappware breach), with the cumulative effect creating substantial identity-fraud risk for Bangladeshi citizens. Tappware has not made a substantial public statement regarding the breach.

Data Points Exposed

9 verified field types
Date of Birth High
Email Address
Full Name
Gender
Government ID Critical
Job Information
Phone Number
Physical address High
Religion

Breach Impact

The institutional impact on Tappware has been moderate based on publicly available information, with Tappware continuing to operate following the breach. Bangladesh's data-protection legal framework was less developed than EU or U.S. equivalents at the time of the breach, although Bangladesh has been progressing toward more comprehensive personal-data legislation. Civil litigation exposure has been limited based on publicly available information. The reputational impact has concentrated within the Bangladeshi enterprise IT services sector and within the broader Bangladeshi cybersecurity discussion of repeated identity-data exposures during 2023-2024. The case has been formally cited in BCSI commentary as illustrating the security weaknesses of Bangladeshi identity-verification service providers and the need for more comprehensive cybersecurity standards across the sector.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Employment-based social engineering using job and employer data

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation