BANGKOK – For a few hundred baht, someone in Thailand could reportedly search for a person’s national ID details, address, vehicle information, and driver’s license records through an online service. The exposed information included records linked to Prime Minister Anutin Charnvirakul, cabinet members, and other prominent people.
The incident was serious, but it was only one part of a much larger problem. Over the past five years, data connected to most of Thailand’s population has reportedly appeared in separate leaks, including medical records, salaries, national ID numbers, photographs, and addresses. At the same time, Thailand continues to move public services online through its Thailand 4.0 strategy. The question is whether government systems can protect the personal information they increasingly require.
A Few Hundred Baht Could Reveal Sensitive Personal Data
Thailand’s latest reported data exposure showed how quickly private information can become a commodity. People with an internet connection and a few hundred baht could request details normally restricted to government officials, according to the investigation described by The Nation Thailand.
The information reportedly included:
- National ID details
- Driver’s license information
- Vehicle registration records
- Car details
- Home addresses
- Other personal information held in government databases
The service reportedly included searches involving Prime Minister Anutin Charnvirakul and members of his cabinet. That detail made the incident impossible to dismiss as a minor leak affecting unknown individuals. Government databases had exposed information connected to some of the country’s most visible public figures.
For less than $10, users could reportedly request personal information normally reserved for state officials.
The case also raised a wider concern. Even when one data leak doesn’t provide enough information to complete an identity verification process, scammers can combine it with records from other breaches. A vehicle record, address, salary, medical history, and national ID number can become far more useful when placed together.
The leak was connected to the Department of Land Transport
Investigators traced the latest incident to Thailand’s Department of Land Transport, known as the DLT. The agency handles driver’s licenses and vehicle registrations, so its systems hold a large amount of information connected to Thai residents and their cars.
Fraud networks allegedly found and shared a way to access protected DLT databases. However, investigators did not initially find evidence that attackers had broken directly into the DLT system.
Digital Economy and Society Minister Chai-chanok Chidchob said access appeared to be connected to one IP address and one account. That account was used twice to obtain information. Investigators considered the possibility that someone had obtained the account password or that access had been granted unlawfully.
The distinction matters because a direct system hack and an abuse of legitimate credentials require different responses. A database may have strong technical defenses, yet still be exposed if an authorized account has a weak password, excessive permissions, or no additional login verification.
A blockchain specialist found the data service
The key discovery didn’t come from the government’s main interagency investigation. Tanarat Kaewawatanaporn, a blockchain specialist and CEO of Thai technology company DomeCloud, found a website advertising personal data search services.
The portal allowed customers to request information that would usually be available only to DLT officers or other state officials. Tanarat’s discovery showed that the data wasn’t merely sitting unnoticed inside a government system. It had allegedly entered an underground market where people could pay to search for specific records.
The incident also appeared less like an attack carried out through extraordinary technical skill and more like a failure of account security and access controls. Someone may have found a way to use a legitimate account, and the system apparently allowed that access to continue without detecting or stopping the misuse.
Government accounts were suspended
Once officials linked the exposure to the DLT, the department suspended user accounts connected to three government bodies:
- The Bangkok Noi District Office Municipal Enforcement Unit
- The Expressway Authority of Thailand
- The Surasee Force of the Royal Thai Army
The DLT said the information taken from its databases couldn’t, on its own, complete identity verification for a single person. That may limit the immediate risk from this one incident, but it doesn’t make the exposed records harmless.
Identity thieves rarely depend on one database. They collect small pieces of information and combine them. Thailand’s recent breach history has given criminals many opportunities to assemble those pieces.
The latest leak was only one part of a larger pattern
The DLT incident followed several other major exposures involving Thai citizens. Taken together, those cases suggest that the country’s data security problem isn’t limited to one department or one poorly protected account.
Thailand has a population of about 71 million people. In the cases described in the video, reported exposures included data connected to 67 million people in one medical incident, 55 million people in the Mor Prom case, and another 20 million people in a later breach.
The types of information involved have included:
- Medical records and vaccination information
- National ID numbers
- Salaries
- Government-service photographs
- Addresses
- Vehicle and registration records
- Shareholder information
Thailand’s cybersecurity risks and regulations are becoming harder to separate from ordinary public administration because so many government services now depend on large databases.
Medical data connected to 67 million people
Several months before the DLT incident, Tanarat led a civil group seeking official action after it found that medical information connected to 67 million Thai people had been exposed.
The reported figure was close to the country’s total population. Medical data is especially sensitive because it can reveal health conditions, treatment histories, vaccination records, and other details that people normally share only with healthcare providers.
That information can also make fraud attempts more convincing. A scammer who knows a person’s health history may be able to create a believable message about an appointment, prescription, insurance claim, or hospital payment. Even when criminals don’t use the information immediately, exposed medical records can remain available for future scams.
About 200,000 shareholders’ information was exposed
Thailand Securities Depository Company Limited, the country’s stock exchange registrar, also suffered a breach involving the personal information of about 200,000 shareholders.
This case shows how personal data can be exposed across different parts of the economy. Government offices aren’t the only organizations holding valuable records. Financial institutions, healthcare providers, transport agencies, and public-service platforms all maintain databases that can interest scammers.
Each incident may reveal a different type of information. The danger grows when a criminal can connect the records.
Separate leaks can create a detailed personal profile
A determined scammer doesn’t need to obtain every detail from one system. One breach might provide a national ID number. Another could reveal a home address. A separate incident could expose a salary, medical record, or photograph.
Taken together, those records could give a criminal a much clearer picture of someone’s life. The same method could be used against an ordinary resident, a business owner, or a senior government official.
The information from the DLT breach may not have been enough to complete identity verification by itself. However, that protection depends on other databases remaining secure. When repeated breaches affect millions of people, the risk comes from the combination as much as from any single leak.
Mor Prom turned a health service into a major privacy concern
Thailand launched the Mor Prom app, which means “Doctor Ready,” during the COVID-19 pandemic. The app originally helped people schedule COVID-19 vaccinations and supported Thailand’s mass vaccination campaign, despite problems during its early rollout.
After the pandemic emergency eased, Mor Prom expanded into a broader health service. Patients could use it to carry medical histories, share records with hospitals, book doctor’s appointments, and track universal healthcare entitlements.
Those features made the app more useful, but they also increased the amount of sensitive data connected to it. A service that begins as a vaccine booking tool can become a large repository of health and identity information when new functions are added over time.
The 9 Near case
In April 2023, a hacker using the name 9 Near threatened to expose the personal data of 55 million Thai people. To show that the information was genuine, the hacker posted sample records linked to prominent individuals.
Authorities matched the sample data to vaccination information entered through Mor Prom. That connection triggered widespread concern about a possible breach involving the app’s database.
The Cybercrime Investigation Bureau later identified the hacker as Sergeant Major Kamarut Bunchoed, an officer in the army transportation department. He avoided arrest for several weeks before turning himself in.
The case showed the danger of placing large amounts of health information in one digital service. Centralized systems can make public services easier to use, but one failure can expose records belonging to millions of people at once.
Another 20 million records were exposed in 2024
The following year, another breach reportedly exposed the records of about 20 million people, most of them senior citizens.
The exposed information included:
- Full national ID numbers
- Salaries
- Photographs taken for government services
Those details can be valuable to criminals who target older people with fake government notices, financial requests, or benefit-related scams. Senior citizens may also face greater difficulty determining whether a message is genuine when it includes accurate personal information.
Twenty million records, including national IDs, salaries, and photographs, create a serious exposure even when no single record contains every detail about a person.
A privacy review found thousands of weak organizations
After the high-profile leaks, the Office of the Personal Data Protection Committee, or PDPC, conducted a privacy sweep. The results pointed to a problem that extended well beyond the systems involved in the most visible cases.
The PDPC flagged more than 5,200 organizations for data protection failures. About 4,800 of those organizations were government offices.
| Finding | Reported number |
| Organizations flagged for data protection failures | More than 5,200 |
| Government offices among those flagged | About 4,800 |
Those figures suggest that government agencies are not only responding to Thailand’s data security problem. They also account for most of the organizations identified in the review.
Digital services also struggle with basic reliability
Security isn’t the only problem. Thailand’s public-facing digital services have also suffered technical failures at times when residents needed them most.
The Social Security Office spent more than 800 million baht, or about $24 million, on an IT overhaul that included a new website and public-facing software. Yet the system continued to crash, locking millions of people out of their benefits.
These failures create a different kind of harm. A security breach exposes information to unauthorized people. A service outage prevents authorized users from accessing benefits they may depend on. Both problems weaken public confidence in digital government.
People are more likely to trust online public services when the systems work consistently and protect their information. Repeated crashes and data exposures undermine both expectations at once.
Thailand 4.0 explains the push toward digital government
Thailand 4.0 became a central policy idea around 2016. Policymakers wanted to move the country beyond an economy based mainly on agriculture and conventional manufacturing. The plan focused on innovation, technology, and higher-value industries.
Digital government was part of that shift. Public services in education, agriculture, tourism, and environmental management were expected to become more convenient, transparent, modern, and responsive.
Thailand has since introduced a wide range of digital platforms. Some services are now available mainly through websites and mobile applications, which means residents may have few practical alternatives when those systems fail.
Government apps built around personal data
Several platforms mentioned in the video show how much personal information Thailand is moving into digital services:
- Thai Dee is a digital ID and face-verification app that allows Thai citizens to use a phone as an identity document.
- RD Smart Tax allows taxpayers to file personal income tax returns with the Revenue Department.
- THIM is an Immigration Bureau app designed to simplify traveler registration.
- Mor Prom supports health records, doctor’s appointments, and universal healthcare entitlements.
These services can reduce paperwork and make routine transactions faster. At the same time, every platform creates another place where personal information must be collected, stored, accessed, and protected.
Thailand’s new smart-device security rules show how data protection concerns now extend beyond government databases to connected devices and other systems that collect information.
International recognition has not solved domestic weaknesses
Thailand improved its position on the 2024 United Nations E-Government Development Index, moving from 55th place to 52nd. It ranked second in Southeast Asia, behind Singapore. The 2024 UN E-Government Survey provides the broader framework for comparing digital government development across countries.
A better ranking shows that Thailand has made progress in building online public services. It doesn’t prove that the systems behind those services are secure or reliable.
Thailand may be moving up the e-government rankings while still struggling to protect the data those services require. A good digital service needs more than an app, a website, or a modern interface. It also needs strong access controls, trained staff, clear rules, and regular testing.
The cybersecurity gap could grow with AI
Thailand 4.0 was created about a decade ago, before AI changed the speed and scale of cyber threats. Policymakers couldn’t have predicted every way AI would affect security.
Today, AI systems can help find weaknesses in software and networks. They can also support automated attacks and coordinate tasks between different tools. The more quickly attackers can search for flaws, the harder it becomes for agencies to rely on slow, manual security reviews.
Thailand’s current problems often involve basic failures, such as shared passwords, weak account controls, or inconsistent security practices between agencies. Those weaknesses become more serious when automated systems can discover and exploit them faster than human teams can respond.
The World Bank’s work on digital and AI systems highlights the need for countries to build the technical capacity required to use these technologies safely.
Thailand has a shortage of technical staff
A World Bank report cited in the video found that about 0.5% of Thai civil servants worked in IT as of 2023. Even fewer worked as cybersecurity specialists.
That staffing gap affects every stage of data protection. Agencies need people who can monitor access logs, secure databases, test applications, respond to incidents, and fix weaknesses before criminals find them.
The report is several years old, so conditions may have changed. Still, the rapid development of AI makes skilled security staff more important, not less. A government that keeps adding digital services without adding enough technical expertise may create systems it cannot properly maintain.
Agencies lack one unified data governance policy
The World Bank report also found that Thailand lacked a single, unified data governance policy. As a result, agencies may apply rules differently and maintain different security standards.
That inconsistency creates weak points across the public sector. A well-protected agency can still exchange data with another office that has weaker controls. Personal information may then move through systems with different login requirements, monitoring practices, and response procedures.
A large number of separate platforms also increases the number of possible failure points. Without common rules, each agency may make its own decisions about who can access information, how long records are kept, and how quickly a breach must be reported.
How Thai authorities are responding
Prime Minister Anutin Charnvirakul ordered government agencies to investigate the latest exposure, identify its cause, determine responsibility, and raise security standards across the public sector.
The National Cybersecurity Agency received 30 days to assess information systems across about 300 government departments. Officials were told to identify weaknesses and require urgent follow-up measures from offices that were found to be vulnerable.
Thailand has also strengthened its legal response to online fraud and unauthorized data disclosure. The country’s cybercrime laws and victim protections include penalties for people who disclose personal information without consent.
Multi-factor authentication becomes the new standard
The public sector will implement multi-factor authentication, or MFA, as a standard security measure.
MFA requires users to provide more than one form of proof when they log in. A password might be paired with a code sent to a phone, a hardware security key, or another verification method.
That extra step could have made unauthorized access harder in the DLT case, particularly if someone obtained or misused an account password. MFA can’t solve every security problem, but it reduces the damage caused by stolen passwords.
New public-sector standard: government systems will use multi-factor authentication to strengthen account security.
The PDPC’s three-level response
The PDPC described a three-part response to personal data leaks:
- The agency will pursue people who distribute or advertise protected data.
- Organizations responsible for holding personal information must contain and report incidents while strengthening their security.
- Authorities will target networks involved in unauthorized access or the trade in personal information.
These measures focus on stopping illegal activity and responding after a breach occurs. They are necessary, but they are mainly reactionary. Thailand also needs consistent prevention measures that apply before private information reaches an underground market.
Reaction alone won’t protect Thailand’s digital future
Thailand’s repeated data breaches reveal several connected weaknesses: poor access controls, unreliable public platforms, thousands of organizations with data protection failures, too few IT specialists, inconsistent data governance, and new risks linked to AI.
The exact timing of the next leak is impossible to predict. Preparation can still reduce the damage. That means agencies need regular security testing, clear access rules, effective monitoring, trained staff, and a reliable process for reporting and containing incidents.
The next breach may contain more than a car registration or home address. It could combine identity records, medical information, salaries, photographs, and account details into a profile that makes fraud easier to carry out.
Thailand’s experience also matters outside the country. Governments everywhere are moving more services online and collecting more personal information in the process. Digital government can make life easier, but convenience depends on public trust. That trust disappears when people must hand over sensitive data to systems that repeatedly expose it.




