Thairath Online
Thairath Online

Summary of TSD Data Breach Incident: Shares Secure, Transactions Safe, Vulnerability Closed

Capital market28 Jul 2026 13:59 GMT+7

Share

Summary of TSD Data Breach Incident: Shares Secure, Transactions Safe, Vulnerability Closed

TSD held a press conference regarding the data breach affecting about 200,000 investors from the Investor Portal system. The accessed data included full names, ID card numbers, and bank account numbers, but TSD confirmed there was no impact on stock holdings or trading transactions. They identified a single perpetrator and have since closed the vulnerability. Meanwhile, cyber police warned that the greater threat is scammers who may use this data to "re-fraud" by impersonating officials.

The Thailand Securities Depository Co., Ltd. (TSD) detected unauthorized access to some personal data of users of the TSD Investor Portal system on 25 Jul 2026. Subsequently, after coordinating with the Technology Crime Suppression Division (TCSD) on 27 Jul 2026 to promptly track down the offender for prosecution, TSD discovered that additional personal data had been affected.

Data affected

  • Full name, date of birth, national ID number, and address
  • Phone number and email
  • Brokerage firm name and securities trading account number
  • Bank name and bank account number

Event timeline

  • Saturday, 25 Jul (evening): The IT team detected abnormal access to the TSD Investor Portal system.
  • Sunday, 26 Jul (morning): Investigation found unauthorized access to some personal data. Authorities, brokers, and custodian banks were promptly notified, and the first batch of affected users received email/SMS alerts. A public statement was also issued.
  • Monday, 27 Jul: TSD filed a complaint with cyber police (TCSD). Joint in-depth investigation revealed that users' "bank deposit account numbers" had also been leaked. A second round of email and SMS alerts was sent to additional affected users on the same day.

What happened with the TSD Investor Portal?

Thiraphan Sanpakit, Deputy Manager and Head of IT at the Stock Exchange of Thailand, explained that there was one perpetrator, an actual user of the TSD Investor Portal who logged in normally but exploited a code modification in the User Profile ID section to extract profile data of over 200,000 users, including securities and bank account information.

In simple terms, this was not an external system hack but an authorized login exploiting a web system vulnerability present for over five years.

Once detected, the Stock Exchange's IT team immediately closed the irregular access point, suspended the perpetrator's account, and fixed the vulnerable code. Importantly, TSD also deployed AI to scan the entire TSD system code and other related systems for similar risk patterns to prevent recurrence.

ถิรพันธุ์ สรรพกิจ รองผู้จัดการ หัวหน้าสายงานเทคโนโลยีสารสนเทศ ตลาดหลักทรัพย์แห่งประเทศไทย

Stock Exchange executives confirmed that this incident does not cause investors to lose their stock portfolios because the system architecture is divided into two completely separate parts. The accessed system was the "front-end" TSD Investor Portal, which is a web-based information view only.

The "back-end" system, which matches trades and stores actual portfolio data, is not connected to the public internet, creating an additional security layer preventing hackers from accessing the core database.

Long-term plans include migrating services from the web portal to the Wiset application, a newer technology with higher security standards.

Regarding confusion about receiving warning emails despite not being affected, Pichaya Chomchaiya, Assistant Manager, Head of Securities and Benefits Services, and Managing Director of TSD, clarified that after the incident, TSD coordinated with brokers, some of whom chose to "send warning emails to all their clients" as a precaution.

Simply put, only those who received SMS or emails directly from TSD were actually affected, while broker emails were preventive alerts.

พิชยา ชมชัยยา ผู้ช่วยผู้จัดการ หัวหน้ากลุ่มงานดูแลหลักทรัพย์และสิทธิประโยชน์ และกรรมการผู้จัดการ บริษัท ศูนย์รับฝากหลักทรัพย์ (ประเทศไทย) จำกัด

The main caution going forward is the risk of "re-fraud" by scammers impersonating officials.

Police Lieutenant Pakrit Kritayapong, Cybersecurity Division Superintendent at the Technology Crime Suppression Division (TCSD), said cyber police are working with cybersecurity partners such as ThaiCERT to trace cross-border data access by examining IP addresses and log files. They affirmed that the perpetrator will be prosecuted under the Computer Crime Act, with additional charges pending investigation results.

The key warning to the public is about layered scams following this crisis: once data is in criminals' hands, fraud methods become more sophisticated. Examples include:

  • VIP-level call center scams or Spear Phishing, where criminals who know your ID number or bank account can lower your guard (Zero Trust), and when they recite accurate personal details, victims instinctively trust them as legitimate officials, such as brokers' marketing staff or bank representatives.
  • Domain Spoofing, where scammers create fake websites resembling the Stock Exchange's, using suspicious free domains like .xyz or .cc. Police recommend verifying official domains such as .th or .ac.th which are more trustworthy.

Therefore, the public should be aware that real officials never call asking for passwords, OTPs, or money transfers. If receiving suspicious calls citing this incident, hang up and contact the institution directly through official channels.

พ.ต.ท.พากฤต กฤตยพงษ์ สารวัตรกลุ่มงานรักษาความมั่นคงปลอดภัยทางไซเบอร์ กองบังคับการตรวจสอบและวิเคราะห์อาชญากรรมทางเทคโนโลยี (บก. ตอท.)


TSD confirms stock portfolios remain safe; no need for alarm.

TSD affirms that no stock holdings or trading transaction data have been compromised in this incident, emphasizing affected users should not panic because the accessed data cannot be used to alter stock ownership or conduct trading.

However, TSD urges users to exercise caution and mindfulness in all transactions, advising:

  • Be wary of emails, SMS, or phone calls impersonating agencies seeking personal data, passwords, or verification codes (OTP).
  • Do not click links, download files, or open documents from unverified sources.
  • Never disclose passwords, OTPs, or personal information to unknown or unverified contacts.
  • Regularly change online account passwords and avoid reusing the same password across multiple services to minimize misuse risk (standard cybersecurity practice, not due to password leakage in this incident since passwords were not among leaked data).
  • Regularly monitor your accounts and related transactions for unusual activity.
  • If you receive emails from TSD, ensure they come from SETContactCenter@set.or.th only and contain no links.

TSD sincerely apologizes for this incident and commits to promptly enhancing system security measures to restore confidence and protect users' personal data to the highest degree.

For stock and investment news, visit Thairath Money at

Follow the Thairath Money Facebook page at this link