Tappware Data Breach (2024)
If you are a customer of Tappware, here’s what’s now in circulation.
In April 2024, a substantial volume of data was taken from the Bangladeshi IT services provider Tappware and published to a popular hacking forum. Comprising of 95k unique email addresses, the data also included extensive labour information on local citizens including names, physical addresses, job titles, dates of birth, genders and scans of government issued national identity (NID) cards.
Tappware customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On April 23, 2024, Bangladeshi IT services provider Tappware appeared in a new breach listing on Have I Been Pwned, confirming that records belonging to 95,000 individuals had been published on a popular hacking forum earlier that month.
Reported Details from the Breach Listing
The disclosure indicates that attackers extracted a substantial volume of personal and employment-related information. Exposed data includes names, physical addresses, email addresses, phone numbers, dates of birth, genders, job titles, religions, and scans of government-issued national identity (NID) cards. The listing does not specify the exact attack vector or whether the data was first offered for sale privately before appearing on the forum. It also does not detail the precise number of NID card images obtained or whether any internal Tappware systems were named in the leak.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Why This Matters for You and Your Family
If you or any member of your household ever worked with or through Tappware, your full contact details, employment history, and government identification are now in the hands of unknown parties. In Bangladesh, where NID cards serve as the foundational identity document for banking, mobile connections, taxes, and government services, the exposure creates immediate risks of impersonation and financial fraud. Even if you do not live in Bangladesh, the combination of home address, phone number, date of birth, and government ID can be used to target family members through phishing, SIM-swapping attempts, or loan applications opened in your name.
The Doxxing and Identity-Chain Implications
Once names, addresses, and government IDs are public, attackers can rapidly link them to social-media accounts, children’s school records, and family relationships. A single leaked NID scan often contains a permanent national identifier that appears in multiple other government and private databases, turning this breach into the starting point for long-term identity chains. Credential leaks of this nature also cascade into account takeovers on email, banking, and gaming platforms. Children’s gaming accounts tied to a parent’s email or phone are particularly vulnerable because the same leaked details can be used to reset passwords and bypass recovery questions.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, including any NID data that may have surfaced on additional platforms.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your information is caught in hours rather than months.
- Rotate every password you ever used at Tappware or any Bangladeshi employer and replace it with a unique passphrase; enable 2FA through an authenticator app on all associated accounts.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts which frequently chain back to the same leaked addresses and phone numbers.
- Let remediation specialists handle takedown requests for any data-broker listings or forum posts that continue to spread your NID scans or home address.
The Tappware breach is a reminder that even mid-sized service providers holding government identity documents can become gateways for widespread personal exposure. A forward-looking approach means treating every leaked record as the first link in a potential doxxing chain rather than an isolated incident. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts at risk from cascading credential leaks.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…