BD-S07Report Incident form
BGD e-GOV CIRT
Shows fields for affected domains, logs, timing, impact and technical evidence in a cyber-incident report.
Open official sourceA KYC request can be part of an identity-control process, but a fake domain can also use the same language to steal documents. Verify the entity, domain, timing and data handling before sending anything.
Record the exact domain or app package, the requesting company, request channel, document requested and stated purpose. Inspect the full sender address and link destination, not only the display name. Check whether the same request appears inside the authenticated account. Pause uploads to an unknown app, shared drive, messaging account or personal email. Urgent countdowns and demands for an immediate selfie to release a withdrawal warrant additional verification.
The KYC acronym is not proof of legitimacy. Ask which jurisdictional rule is relied on, which legal entity collects the data, who processes it, how long it is retained, how correction or deletion works and where a breach is reported. When those answers are absent, data risk remains unknown. The truth of a foreign licence and the lawfulness of collecting data from Bangladesh are separate questions.
| Requested data | Particular risk | Lower-data question |
|---|---|---|
| Identity document front and back | Identity reuse, address and number exposure | Are all fields necessary; is masking accepted |
| Selfie or liveness video | Biometric reuse and impersonation | Which processor and retention period |
| Bank or MFS statement | Account, balance and unrelated transactions | Can the date range and fields be limited |
| Source of funds | Employer, income and family privacy | Which threshold and evidence basis |
| Card image | Number, expiry and signature exposure | Will a masked issuer record work |
| OTP, PIN or password | Immediate account takeover | Never provide it |
Compare timestamps for registration, first deposit, bonus acceptance, withdrawal request, KYC demand, upload and account block. A requirement first disclosed after withdrawal is important evidence, but not a fraud verdict by itself. Ask whether the policy was accessible beforehand, whether acknowledgement was recorded and whether the rule appears to be applied consistently.
Capture the exact restriction message. Login disabled, verification pending, security review, duplicate account, location restriction and closure are not equivalent. Loss of access does not prove confiscation or decide ownership of a balance. Ask support for the cited clause, expected review time, appeal route and status of each submitted document.
Keep the original submission message, upload acknowledgement, file names, date and recipient. Do not attach the identity file to a public complaint. Change reused passwords for email, phone and wallet accounts, then review active sessions. Before removing an unknown app, note its file name, source URL and the security event. Use a clean device if compromise is suspected and preserve the affected domain and impact for a possible CIRT report.
Do not assume identity misuse has occurred, and do not say it has been ruled out. Maintain a dated log of new-account alerts, SIM changes, password resets and unauthorised transactions. Showing an original privately to the appropriate provider or police is not the same as publishing it online.
Specify whether you seek account access, withdrawal review, deletion confirmation, correction, the status of submitted files or a security investigation. Keep the casino complaint separate from the payment-provider complaint. An MFS provider can address its own account and transaction, not necessarily the casino's identity processing. Technical phishing or malware evidence may fit CIRT; suspected criminal misuse may fit police.
When the operator replies, the verified fact is that a response was received on a date and stated a reason. Do not adopt the reason as true without independent evidence. Preserve appeal deadlines, but do not treat a new fee or further identity transfer as an automatic condition.
Do not publish the sensitive document itself.
List file name, document type, covered period, request date, submission date, channel, acknowledgement and redaction status. This can explain the sequence without distributing a complete identity bundle. Compare any repeat-upload demand with the earlier acknowledgement.
Give a modified or resized document a different file name from the original. A public account usually needs the request and submission event, not the identity image itself.
Name, age, address, payment ownership and source of funds serve different purposes. Ask who controls the data, which channel is secure, how long it is retained, how deletion works and where a breach is reported. Verify the official account channel before sharing a complete document in chat. Ask whether lawful redaction can hide unrelated transactions or background details; do not alter a document on your own. Track the data request, balance dispute and access complaint separately because resolving one does not automatically resolve the others.

BD-S07BGD e-GOV CIRT
Shows fields for affected domains, logs, timing, impact and technical evidence in a cyber-incident report.
Open official sourceBD-S09BGD e-GOV CIRT
Records a dated campaign involving fake software, malware and local-payment lures; it does not justify claims about unrelated domains.
Open official sourceBD-S15Bangladesh Bank
Lists MFS services including bKash, Nagad and Rocket and identifies their business entities.
Open official sourceThis advisory concerns a named campaign and cannot be generalised into an adverse finding about another casino or KYC system. Each source supports only the narrow proposition stated beside it. Recheck the live authority page before acting. Search snippets, advertising, forums and operator statements are not proof by themselves.
Safety cannot be established without checking the exact entity, domain, purpose, necessity, secure channel, retention and complaint route. Pause when uncertain.
No. OTPs, PINs and passwords are account-control secrets, not identity documents.
No. It is an access event. Avoid a criminal conclusion until balance, reason, policy, withdrawal state and stronger authority evidence are known.
Preserve submission evidence, change reused credentials, monitor accounts and choose provider, CIRT or police routes according to actual phishing, malware or misuse facts.