-
An unknown hacker says they broke into the internal network of the Bangladesh Army.
-
The target is the Qadirabad Cantonment headquarters, according to a dark web listing.
-
The actor says an outdated MikroTik router exposed more than 50 internal networks and 400 live devices.

An anonymous actor posted a claim that the Bangladesh Army’s network has fallen completely under their control. The listing focuses on the Qadirabad Cantonment headquarters.
The actor says the attack began at the base’s main router. The post also shares many technical details to back up the claim.
The Bangladesh Army is a major national security force. Qadirabad Cantonment serves as an important logistics and administrative hub. The listing describes what the hacker says they can now see and use. It also says the breach exposes critical operational details about the base.
Old Router Software Allegedly Opened the Door
The hacker says the attack started with one device. It is a MikroTik CCR1036-8G-2S+ router with the IP address 27.147.148.184. A router is the box that sends data between networks. The post calls it the primary router of the base. The listing says it runs RouterOS version 6.49.18, an outdated version.
The actor says three services sat open to attackers. These were SNMP, Winbox, and SSH. SNMP lets tools read a device’s status. Winbox is MikroTik’s own management tool. SSH is a way to log in to a device from far away. The post calls all three exposed, which means outside users could reach them. The hacker says they used these services to map the entire base network.
The listing also names a specific flaw in Winbox. It is tracked as CVE-2018-14847. The actor adds that SSH and SNMP have unpatched weaknesses too. Patches are fixes that close such gaps. The post says the router never received them.
The hacker claims access to sensitive connections linked to Link3 Technologies. The post names Link3 as the service provider. The actor also lists network labels tied to different military functions. Two examples are vlan2402-GGC and vlan2403-FNA.
A VLAN splits one network into separate groups, so each label points to a different part of the base. The post says these interfaces connect to the outside provider.
Listing Shows Maps, Passwords, and Device Records
The actor’s list of stolen items starts with a full network map. According to the listing, it shows over 50 internal subnets and more than 400 live devices. A subnet is a smaller section of a larger network. The map gives a clear picture of how the base connects its machines. The actor also lists the full routing table, which shows how data moves inside the base.
Backup files come next. The actor says these files hold passwords in plain text, so anyone can read them. The post also lists RADIUS settings that use weak credentials. Weak passwords are easy to guess. One example is the simple password 123321. RADIUS is a system that checks who may log in to a network.
The hacker lists more items taken from the router. These include user login logs and system diagnostic files. One file carries the name autosupout.rif. Another is a backup file called 15123_1812358-20260513-2247.backup. The listing also shows exact interface statistics. These numbers describe how much data each network port handles.
The actor says the data reveals over 100 active PPPoE connections. These are links that customers or devices use to get online. The post also lists MAC addresses for connected servers, computers, and VoIP phones. A MAC address is a unique ID that every network device carries. VoIP phones are phones that make calls over the internet.
The hacker claims another prize too. They say they pulled the hotspot folder from the router. It holds HTML, CSS, and JavaScript files. The wireless internet login page uses these files. People see this page when they join the base’s Wi-Fi. The post says attackers could use them to compromise people who connect to that page. That would put every user of the wireless portal at risk.
Officials have Not Confirmed the Military Network Breach
The technical details in the post look very specific. The listing gives an IP address, a software version, file names, and exact numbers. Even so, official sources have not verified the incident.
Bangladesh has also faced other reported cyber incidents affecting different sectors, including the cases covered in Bangladesh faces dual cybersecurity breaches across government and retail sector
Nobody outside the hacker has confirmed that the data is real. The claim about the router, the flaws, and the stolen files all rest on the listing alone.
If the claim is true, the exposed data could give attackers a strong start. Routing tables show how data travels between the base’s networks and outside networks. Device credentials open doors to individual machines. Together, they could let attackers move from one system to another inside the network.
They could also aim at military communication systems. The listing says the base’s servers, computers, and phones all appear in the exposed records. At the time of reporting, nobody has independently verified the alleged breach.