
In an age when retrospective verification technology exists, why are the most confidential exam data still stored on 2000s-era devices like Flash Drives? Especially when the original answer sheets are locked securely with two separate keys, yet scanned files and all scores are transferred on Flash Drives that do not indicate who accessed them.
Amid the 2025 local government civil service exam fraud case escalating to the point where the Prime Minister ordered urgent cancellation of exam results related to the fraud according to principles,"The theory of the poisoned fruit"there is a technical detail in the statement by the Educational and Psychological Testing Center of Srinakharinwirot University (SWU) that many overlooked quickly.
From a technology perspective, this is a point that raises questions: the score files, classified as "top secret"were recorded onto Flash Drives for delivery to the client.
According to the Terms of Reference (TOR) specified by SWU, after completing answer sheet checking at 10 exam centers, the contractor must create score data files in .pdf and .xlsx formats, as well as scanned answer sheets in .pdf or .jpg, save them on Flash Drives, and immediately deliver them to the Department of Local Administration, with the confidentiality level set as"top secret."
Meanwhile, original answer sheets are stored in a secure room monitored by 24-hour CCTV and secured with a dual-key system held separately by SWU and the department; opening the room requires both parties simultaneously.
Overall, it shows that the paper documents are protected by high-level measures including secure rooms, CCTV, and dual-key control, reflecting the principle"no one can access alone."However, the digital data—which is the core of score processing—travels on a device designed for convenience like a Flash Drive, which is portable and not designed for confidentiality.
This asymmetry is striking: on one side, paper documents are safeguarded in a vault-like room, but digital protection is a fragile fortress full of vulnerabilities.
It must be clarified that so far there is no evidence that Flash Drives were the data leak point in this case. The fraud caught by the police and anti-corruption agencies on 22 June 2026 in Bang Yai district, Nonthaburi province involved altering scanned answer sheets in the computer system to match pre-determined passing candidates who had paid bribes of 350,000-800,000 baht each. Therefore, Flash Drives are not"the culprit" in this matter.
The unavoidable question is: since Flash Drives are technology from the early 2000s, why is the delivery of nationally important data still tied to Flash Drives when more secure, retrospectively verifiable technologies exist today? The answers include rational explanations and some points that invite suspicion.
The rational explanations start with the logic of confidentiality levels themselves. Data classified as"top secret" in many agencies is often deliberately kept offline because being disconnected from the internet reduces the risk of remote attacks.
Since Flash Drives are physical devices, they are seen as a safer option.
Second is the inertia of TORs and government procurement systems, where requirements are copied year after year with minimal technical updates to keep pace with current technology.
Third are budget and skills limitations: establishing encrypted file transmission and storage systems with comprehensive access logs requires investment and cybersecurity personnel that many agencies still lack. Lastly, Flash Drives are easy to use—they work on almost any computer without configuration.
In other words, it is not that"new technology cannot be used,"but rather the old"is easy, cheap, and no one forces a change." This aligns with the view of Than Radsanukul, CTO of a private cloud technology company, who noted that government policy lagging behind technology trends is common. He gave the example that just a few years ago, government agencies still exchanged data on CDs or DVDs.
However, Than interestingly pointed out that for such tasks, using write-once or hard-to-alter media like CDs or DVDs might actually be more suitable than Flash Drives, because these media inherently resist later data modification—though they have fallen out of favor.
This perspective sharply reflects the core problem because the breach in this case involved
"the ability to modify data."Therefore, choosing media or systems that make data unchangeable or immediately detect changes is more crucial than debating which Flash Drive generation to use.On the other hand, a less comfortable but necessary observation is that technologies that are
"better"often come with features that make fraud"more difficult to execute."Systems that log every access, use digital signatures that detect even a single digit change, or require multi-party approval reduce"flexibility"that fraudsters exploit through loopholes.Thus, the question may not only be why new technology is not used but whether
"there is reluctance to have a system that is too robust and strict."Because fully transparent, retrospectively verifiable systems are unfriendly to anyone wanting to keep shadowy loopholes.Looking at better alternatives, if physical media must still be used, the minimum should be hardware-encrypted Flash Drives compliant with FIPS standards, requiring PINs to unlock and automatically wiping data after a set number of incorrect attempts.
A safer systemic approach is transmitting data via end-to-end encrypted channels on file transfer systems that log all access, such as Managed File Transfer systems or government data exchange services with full logging, aligning with Thailand's digital government initiatives.
On this point, Than suggests going beyond media choice to storing such data on cloud services with comprehensive access and edit logs. This enhances security and facilitates data transfers between locations without fuel waste from frequent physical transport. He emphasizes that the key is enforcing strict data security policies based on international standards like ISO 27001 or ISO 20000-1.
The most important tool for the context of
"exam scores"is creating digital fingerprints of files via hash encryption and digital signatures from the moment scores are finalized at exam centers.The principle is that each score file has a unique code derived from its contents; any later change, even a single digit, instantly alters this code. This makes detecting alterations to scanned answer sheets in computers, as happened in this case, immediate and straightforward. Than stresses that government agencies should follow international standards promptly, and regardless of media choice, at least store file hash values alongside edit logs. Coupled with immutable logs and multi-party access permissions—akin to the dual-key principle from secure rooms applied digitally—the system gains significant internal tamper resistance.
Nonetheless, it must be acknowledged that no technology alone can defeat"authorized insiders." Many suspects arrested in this case were government officials already authorized to access the system. The solution is not just
"better technology,"but technology designed to limit authorized users' powers through role separation, multi-party approvals, and public transparency allowing external audits. This aligns with widespread observations that solely centralized exam administration is insufficient without transparent, externally verifiable processes.