Thailand has opened a cross-agency investigation after personal data linked to the public, the prime minister, cabinet ministers and senior officials appeared online, including vehicle-registration records held by the Department of Land Transport (DLT).
Authorities said initial evidence points to unauthorised use of compromised login credentials rather than a direct hack of the DLT system. The data was allegedly being sold through illegal online services, including Discord bots.
The case follows an earlier exposure involving about 200,000 investors from more than five million shareholder accounts held by Thailand Securities Depository Co Ltd.
For foreigners living in Thailand, especially those with Thai-registered vehicles or accounts on government services, the immediate concern is phishing, impersonation and scam attempts using genuine personal details. The Personal Data Protection Committee (PDPC) has warned people not to test, download, forward or republish the material, as this could itself be an offence.
Investigation focuses on access and illegal sellers
Police Colonel Surapong Plengkham, the PDPC secretary-general, said the suspected conduct appeared to fall under Section 7 of the Computer Crime Act, covering unauthorised access to protected computer data, rather than a conventional database leak.
The PDPC's response has three strands. It is pursuing people who post data or links providing unauthorised access; requiring the DLT and Department of Provincial Administration to investigate, report breaches and improve security; and targeting networks selling personal information or access to state systems.
Digital Economy and Society Minister Chaichanok Chidchob said investigators had found no evidence of a direct DLT hack. Access was traced to one IP address and an account used for two log-ins before the information was disclosed. The access route has since been closed.
Chaichanok ordered a ThaiCERT team from the National Cyber Security Agency (NCSA) to work at the DLT, conducting digital forensics, tracing the data and examining API activity with connected agencies.
The DLT said the information was genuine but was basic data that could not be used for other transactions. It warned redistributors they could face legal action.
Deputy minister Nan Boonthida Somchai said social-media publication could help scammers commit online crimes. Section 14 penalties can include up to five years in prison, a 100,000 baht fine, or both.
Password-only systems under scrutiny
Thanarat Kuawattanaphan, chief executive of DomeCloud, said vehicle-registration databases had been openly offered for sale during the past three months. Prominent individuals' records were used as samples to show databases were genuine, he said.
He said Discord bot services reportedly charged 350 baht daily or 2,500 baht monthly for unlimited searches. The DLT records originated from its own system, while Department of Provincial Administration data was traced to that department's website, according to Thanarat.
Many state systems still rely solely on usernames and passwords, he said. On June 10, his checks found leaked-account records linked to the Interior and Education ministries at 500,000 each, Labour at 359,535, Public Health at 212,460, the Prime Minister's Office at 198,984, Defence at 170,667, Justice at 151,626 and Finance at 107,456.
More than 90% were old passwords no longer usable, but could still assist phishing or password-guessing. Thanarat urged agencies to close unused systems and add ThaID authentication, estimating it could cut attacks by about 90%. He also said ThaID capacity must be expanded to avoid outages during heavy demand.

Picture courtesy of The Nation

7 August 2026
Recommended Comments
Create an account or sign in to comment