A politician's most sensitive asset is no longer kept in a filing cabinet. It sits in the phone in their hand. Correspondence, funding, staff lists, private photographs, party discussions and voter data now converge on a single device — and that device is usually protected no better than an ordinary consumer's.
Political work in Bangladesh has gone digital quickly. Campaigning, fundraising, coordinating workers and dealing with the press all run through WhatsApp, Messenger, Telegram and email. Security practice has not moved at the same pace. The result is that a political figure's digital presence is now both the easiest and the most valuable target an adversary can choose.
The threat landscape has changed
Political security used to mean bodyguards, secure vehicles and a guarded residence. All of that is still necessary. But alongside it a new attack path has opened — one where the attacker never has to get close, never has to take a physical risk, and does not even have to be in the country.
Sending a phishing message costs effectively nothing. Buying a leaked password costs very little. Producing a convincing fake audio clip now requires only a few minutes of recorded speech, which any television interview will supply. What was a state-level capability a decade ago is now within reach of any rival, blackmailer or organised group.
In politics, the objective of a cyber attack is often not money. It is information, a leak timed for maximum effect, and reputational damage — none of which appears on a balance sheet.
The evidence, in numbers
This is not a hypothetical risk category. The public record on the targeting of politicians is now substantial, and it comes from forensic researchers, platform vendors and parliamentary bodies rather than from security marketing.
- Spyware targeting is measured in hundreds of politicians, not dozens. The 2021 Pegasus Project — a consortium of 17 media organisations working with Amnesty International and Forbidden Stories — examined a leaked list of more than 50,000 phone numbers. Journalists identified over 1,000 individuals across 50 countries, including more than 600 politicians and government officials, 189 journalists, 85 activists and 65 business executives. Fourteen current or former heads of state appeared on the list, among them the sitting French president.1
- State-backed attacks on high-profile individuals run to tens of thousands a year. Google's Threat Analysis Group sent over 50,000 warnings of government-backed attack attempts in 2021, roughly a third more than the previous year, and around 40,000 in 2019. On any given day it tracks more than 270 government-backed attacker groups operating from over 50 countries. Political campaigns are named explicitly among the high-risk categories it protects.2
- Even the best-resourced campaigns get compromised. The Salt Typhoon intrusion disclosed in October 2024 reached at least nine major US telecommunications providers and abused lawful-intercept infrastructure. Metadata for more than a million users in the Washington DC area was accessed, and the FBI notified both major presidential campaigns and the office of the Senate Majority Leader that they had been targeted.3
- Abuse of politicians online is now the norm, not the exception. A 2025 Inter-Parliamentary Union study of 150 women parliamentarians and parliamentary staff across 33 Asia-Pacific countries found 60% had been targeted by hate speech, disinformation, image-based abuse or doxxing, and 76% reported psychological violence. Across five regions, the IPU has recorded 82% reporting psychological violence during their terms.4
- The regional data environment is leaky by default. In mid-2023 a Bangladesh government portal operated by the Office of the Registrar General, Birth & Death Registration exposed the personal data of an estimated 50 million citizens — full names, phone numbers, email addresses and national ID numbers. The researcher who reported it found the data as the second result of an ordinary Google search for an SQL error message. It remained exposed until it was taken down five days later.5
The last point deserves emphasis for anyone operating in Bangladesh. Adversaries building a profile of a political figure here do not need to breach anything: substantial identity data on the population, including the people around you, has already been exposed through no fault of yours.
Everyday threats: the ones that arrive first
1. Messaging account takeover
Losing control of a WhatsApp or Telegram account is the single most common incident we see. The method is simple: trick the target into handing over a one-time code, or persuade a mobile operator's customer service to reissue the SIM (a SIM swap). Once inside, the attacker does not merely read old messages — they send new ones in your name, to your staff, your colleagues and journalists. The damage lands on your credibility, not just your data.
2. Targeted phishing
Generic phishing is easy to spot. Targeted phishing arrives under a familiar name — a party worker, a journalist, or an invitation from an organisation you actually deal with. It references your real schedule, real colleagues and real events, because all of that is publicly available. Without training, these messages are close to impossible to identify reliably.
3. AI-generated fake audio and video
The danger of deepfakes in politics is not only that people may believe a fabricated statement. The deeper problem is that once fabricated content becomes normal, genuine evidence becomes easy to dismiss. Without a prepared response, the few hours it takes to react to a fake audio clip are, in political terms, more than enough time for the damage to be done.
4. Personal data exposure and doxxing
Home address, family members' identities, children's schools, daily movement patterns — assembled together, these stop being material for online harassment and become a physical security problem. What makes it difficult is that most of this information is never stolen. It is collected from public records, social media and the posts of your own staff.
5. Lateral access through staff and family devices
An attacker rarely goes straight at the leader's phone. They go for the personal assistant, the driver, a campaign volunteer or a family member — where security is weaker, but the same group chats, the same photographs and the same schedule are present. In our experience the largest exposure is almost never on the principal's own device. It is on the devices around them.
Strategic threats: the ones that arrive quietly
The threats above are noisy and eventually noticed. The category below is designed not to be. These operations are patient, well resourced, and measured in years rather than weeks — and for anyone holding or seeking national office, they are the more consequential half of the problem.
6. Foreign intelligence collection and interference
Bangladesh sits on a strategically significant piece of geography, with major powers competing over ports, energy routes, water sharing, trade corridors and regional alignment. Foreign services — regional and further afield — have a standing interest in knowing what senior political figures intend to do, who funds them, who influences them, and what could be used to change their position later.
Collection of this kind rarely announces itself. There is no ransom note and no defacement. The objective is quiet, persistent access to correspondence and intent, maintained for as long as possible. A service that has read your messages for two years does not want you to discover it in month three. Assume that the absence of visible incidents is not evidence of absence.
The same access supports interference: leaking selected material at a chosen moment, funding aligned voices, amplifying divisive narratives before an election, or quietly signalling to you that certain information is held. Compromise is not always used to attack — often it is used to create leverage.
7. Commercial interception and mercenary spyware
Interception capability that once belonged only to major states is now sold commercially. Several vendors market phone-implant products to government customers worldwide; the class has been documented repeatedly by academic and journalistic investigators, and politicians, journalists and lawyers have been among those found targeted.
What matters practically is the delivery method. The most capable products require no interaction at all — no link to click, no file to open. A message arrives and the device is compromised, and the message may then delete itself. Antivirus software does not detect this class of intrusion. The realistic defences are architectural: keep operating systems fully current, enable the hardened modes that vendors now ship for high-risk users, reboot devices regularly to disrupt non-persistent implants, and keep the most sensitive conversations off internet-connected phones altogether.
8. Honey traps and cultivated relationships
The oldest technique in intelligence work has not gone away — it has moved online, and it has become cheaper. The pattern is consistent enough to recognise. Contact is initiated by someone attractive, flattering and unusually well informed about your interests: a supposed journalist, a researcher, a business contact, a party sympathiser, or a romantic approach on a messaging or dating platform. Rapport is built slowly. Nothing sensitive is asked for early.
What follows is one of two things. Either the relationship becomes the collection channel — questions that seem like curiosity, requests to review documents, an offer to help with the campaign that comes with access. Or it produces material: photographs, recordings, or messages that can later be used for pressure. Physical honey traps at conferences, hotels and receptions still occur, but the online version scales, costs nothing and is far harder to attribute.
Two things make this threat different from the others. First, the target rarely reports it, because the circumstances are embarrassing — which is precisely the design. Second, it frequently targets the people around the principal rather than the principal: a private secretary, a driver, an unmarried staff member, or an adult child. The defence is not suspicion of everyone; it is a stated protocol — how new contacts are verified, what is never discussed outside secure channels, and a standing guarantee that a staff member who reports an approach will be protected rather than blamed.
9. Insider recruitment and staff compromise
Access is often bought rather than hacked. A monthly payment to a junior IT contractor, an office assistant or a driver can deliver more than a technically sophisticated intrusion: the contents of a phone, a copy of a schedule, a photograph of a document, or simply advance warning of a meeting. Recruitment may also use pressure — debts, family circumstances, immigration status, or material obtained through the approach described above.
The structural answer is compartmentalisation. No single staff member should need access to everything; sensitive material should be logged when accessed; and access should be removed the day someone leaves, not weeks later. Most political offices we assess have no record of who holds which credentials.
10. Gifted, borrowed and tampered hardware
Phones, laptops, routers, power banks, USB gifts and even vehicle equipment can arrive already compromised. Gifts from new acquaintances, equipment donated to a campaign, and devices bought through an unfamiliar intermediary all deserve the same treatment: they do not connect to anything that matters. The same applies to repairs — an unvetted repair shop has complete physical access to an unlocked device, which is more than most remote attackers ever obtain.
11. Travel, borders and hotels
Travel concentrates risk. Devices can be examined, copied or retained at a border; hotel rooms and safes are not secure against a determined service; hotel and conference Wi-Fi is a routine collection point; and roaming or locally purchased SIMs place your traffic on an unfamiliar network. Political travel is also predictable and often published in advance, which gives an adversary time to prepare.
The standard mitigation is not complicated: travel with clean devices carrying only what the trip requires, keep primary accounts off them, and treat anything that left your possession — even briefly — as no longer trustworthy on return.
12. Metadata and financial records
Content is not the only prize. Call records, message timing, location history, banking and mobile-money transactions and travel bookings together reveal your network, your priorities and your movements — often more reliably than the conversations themselves. Metadata is also easier to obtain, easier to retain and rarely encrypted. A serious adversary maps relationships from metadata first and pursues content second.
13. Coordinated narrative attacks and forged documents
Finally, the material obtained through any of the above is deployed. Genuine documents are mixed with forged ones so that denial becomes impossible; authentic messages are stripped of context; coordinated accounts push a narrative on a chosen day; and a fabricated audio clip lands during the news cycle least favourable to you. Preparation matters more than reaction here — a verification and response process agreed in advance, with your legal and communications teams, is the only thing that shortens the window between publication and rebuttal.
What it has cost, case by case
Career consequences are the part most often left out of security discussions. These are documented incidents, not scenarios.
Poland: stolen messages, doctored, aired during the campaign
Opposition senator Krzysztof Brejza's phone was compromised with Pegasus spyware 33 separate times between April and October 2019 — precisely the period in which he was running the opposition's parliamentary election campaign. Text messages taken from his phone were doctored and broadcast by state-controlled television during the race, which the governing party narrowly won. A Senate committee later investigated; the government denied the surveillance affected the outcome. Whatever one concludes about causation, the mechanism is not in dispute: a campaign manager's private messages became campaign material for the other side.6
Greece: a leadership target, and two resignations at the top
In July 2022 Nikos Androulakis — leader of the PASOK opposition party and an MEP — was informed by the European Parliament of an attempt to infect his phone with Predator spyware. Within weeks the director of the National Intelligence Service and the prime minister's general secretary, who was also his nephew, had both resigned. The political cost of a surveillance scandal landed not only on the target but on the government associated with it.7
Slovakia: a fabricated recording, released when rebuttal was hardest
Two days before Slovakia's 30 September 2023 election, an AI-generated audio clip circulated on Facebook, purporting to capture Progressive Slovakia leader Michal Šimečka and a Denník N journalist discussing how to buy votes. The conversation never took place. What made it effective was timing: it landed inside the 48-hour pre-election moratorium, when candidates and media are legally constrained from campaigning, so the rebuttal was slower than the lie. Researchers caution against attributing the election result to the clip — but the operational lesson stands, and it is about timing, not technology.8
United Kingdom: a honey trap that cost an MP his position
In 2024 a string of people working in Westminster politics received flirtatious WhatsApp messages from senders calling themselves "Charlie" or "Abi", in some cases exchanging explicit images. Conservative MP William Wragg admitted handing over fellow MPs' personal phone numbers to a contact from a dating app, saying he had been frightened. He resigned the party whip and quit his Commons committee roles; a man was subsequently charged with blackmail and communications offences. Security specialists classified the operation as spear-phishing — the objective was compromising material, and the entry point was a personal relationship, not a technical vulnerability.9
Four incidents, four different mechanisms — spyware, a leak, a fabrication, a honey trap — and in each case the measurable damage was political: positions resigned, credibility spent, a campaign fighting its own leaked messages during the final weeks. None of it was repaired by better technology after the fact.
Why now, and not later
Four things have narrowed the window for waiting.
- Attacks have become cheap. Automation and AI tools have turned what once required skill into something that can simply be purchased as a service.
- State-grade capability is now for sale. Commercial interception products have placed implant-level access within reach of buyers who could never have built it themselves.
- The pool of leaked data has grown. By combining credentials leaked from various services, an attacker can establish in advance which platforms you use — the map they need to plan account takeovers and recovery abuse.
- Protection takes time to build. Security is not established in a day. During an election, a movement or a crisis, introducing new measures is effectively impossible: workload is at its highest and tolerance for error at its lowest.
Security works only when it is already in place before the incident. What is done afterwards is not security — it is damage control.
Steps you can take today
Even before a full programme begins, these measures reduce exposure immediately:
- Enable two-factor authentication on every important account — using an app or a hardware key rather than SMS
- Ask your mobile operator to add extra verification before any SIM reissue
- Turn on the hardened high-risk mode your phone vendor provides, keep the operating system fully updated, and reboot daily
- Move sensitive discussions to end-to-end encrypted channels, with disappearing messages switched on
- Separate public and private communication onto different numbers and different devices
- Agree a rule that genuinely sensitive decisions are discussed in person, not on any phone
- Establish a written protocol for new contacts and unsolicited approaches — how they are verified, and who is told
- Tell your staff plainly that reporting a compromising approach will be handled discreetly and without blame; unreported approaches are what become leverage
- Refuse gifted or donated devices on any network that matters, and use only vetted repair channels
- Travel with clean devices, and retire any device that left your possession
- Make basic security training mandatory for personal assistants and office staff
- Separate home and office Wi-Fi, and keep the guest network genuinely isolated
- Keep encrypted backups of critical documents, so a lost or seized device does not stop your work
- Agree a response plan for a leak or a fabricated recording before one appears
What a structured programme looks like
Risk differs from person to person and institution to institution, so a single template does not work. Our process runs in four stages:
- Threat assessment — building a complete picture of the public information, devices and accounts belonging to you and everyone around you
- Security architecture — designing measures around how you actually work, so that security does not slow the work down
- Deployment — configuring devices, networks and accounts, and training your staff
- Managed protection — 24/7 monitoring, regular review, and readiness to respond quickly when something happens
The entire engagement is conducted under an NDA, and no data of yours is retained by us once the work is complete.
In closing
A political reputation takes years to build, and a single leaked conversation or hijacked account can damage it within hours. The question is no longer whether someone will target you. The question is how prepared you are at the moment they do.
If your digital risk has never been formally assessed, that is the most sensible place to begin. You cannot reduce an exposure you have not measured.
Sources
- Forbidden Stories / Amnesty International, The Pegasus Project (2021), reported by OCCRP and The Washington Post — occrp.org, washingtonpost.com
- Google Threat Analysis Group, government-backed attack warnings — blog.google
- Salt Typhoon telecommunications intrusion — Congressional Research Service, NBC News
- Inter-Parliamentary Union, Sexism, harassment and violence against women parliamentarians in Asia-Pacific (2025) — ipu.org
- 2023 Bangladesh government website data exposure — TechCrunch, The Record
- Associated Press investigation into the hacking of Senator Krzysztof Brejza — AP via VOA
- 2022 Greek surveillance scandal — Al Jazeera
- Slovakia 2023 pre-election deepfake — Schneier on Security; on the limits of attributing the result to it, HKS Misinformation Review
- Westminster WhatsApp honey-trap case — BBC News
Figures are quoted as published by the sources listed above and reflect the period each study covers.