
TSD disclosed that personal data of approximately 200,000 investors was leaked from the Investor Portal system. The accessed information included names, national ID numbers, and bank account numbers. However, they confirmed that stock ownership and trading transactions were unaffected. The incident involved a single perpetrator, the vulnerability has been closed, and cyber police warned that the bigger threat is scammers using the data to impersonate officials to deceive victims again. The warning emphasized vigilance against such impersonations.
The Thailand Securities Depository Company Limited (TSD) detected unauthorized access to personal data of some users of the TSD Investor Portal system on 25 July 2026. Following coordination with the Technology Crime Suppression Division (TCSD) on 27 July 2026 to expedite identifying the offender, TSD discovered additional affected personal data.
Affected data included:
Full names, dates of birth, national ID numbers, and addresses.
Phone numbers and email addresses.
Brokerage firm names and securities trading account numbers.
Bank names and bank account numbers.
Saturday, 25 July (evening): The IT team detected abnormal access to the TSD Investor Portal system.
Sunday, 26 July (morning): Investigation confirmed partial access to personal data. Authorities, brokers, and custodian banks were promptly notified. Initial email and SMS warnings were sent to affected individuals, and a public statement was issued.
Monday, 27 July: TSD filed a report with the cyber police (TCSD). Joint deeper investigation revealed that users' bank account numbers were also leaked. Additional email and SMS alerts were sent to affected parties the same day.
Thiraphan Sanpakit, Deputy Manager and Head of IT at the Stock Exchange of Thailand, explained that there was one perpetrator, a legitimate user of the TSD Investor Portal. The individual logged in normally but exploited a code modification vulnerability in the User Profile ID section to extract profile data of over 200,000 users, including securities and bank account details.
In simple terms, this was not an external system hack but rather access through normal channels exploiting a long-standing web system vulnerability that has been active for over five years.
Upon detection, the stock exchange's IT team immediately closed the abnormal access route, suspended the perpetrator's account, and fixed the vulnerable code. Importantly, TSD also employed AI to scan all code across the TSD system and other stock exchange systems to identify similar risk patterns and prevent recurrence.
Stock Exchange management assured that this incident will not affect investors' stock portfolios because the system architecture is divided into two completely separate parts. The accessed system was the "front end," specifically the TSD Investor Portal web system for viewing information only.
The "back end" system, which matches trades and holds the actual portfolio data, is not connected to the public internet. This additional firewall layer prevents hackers from accessing the core database.
In the long term, TSD plans to transition service from the web portal to the Wiset application, which is based on newer technology with higher security standards.
Regarding confusion about why some people received warning emails despite possibly not being affected, Pichaya Chomchaiya, Assistant Manager and Head of Securities and Benefits Management and Managing Director of TSD, clarified that after the incident, TSD coordinated with brokers, many of whom chose to send warning emails to all their clients as a precaution.
In short, only those who received SMS or emails directly from TSD were truly affected. Broker emails were preventive alerts.
Pol. Lt. Col. Pakrit Kritayapong, Cybersecurity Division Inspector at the Technology Crime Suppression Division (TCSD), stated that cyber police are working with cybersecurity partners like ThaiCERT to trace cross-border data access, examining IP addresses and log files. He confirmed that the offender will be prosecuted under the Computer Crime Act, with additional charges pending further investigation.
The strongest warning to the public is about layered scams following the breach, as stolen data in criminals’ hands can make frauds more sophisticated. Examples include:
VIP call center gangs or spear phishing: When criminals know your national ID or bank account numbers, victims' vigilance (Zero Trust) drops immediately. Hearing accurate personal details makes victims believe the caller is a legitimate official, such as a broker’s marketing staff or bank representative.
Domain spoofing: Creating fake websites resembling the Stock Exchange’s official site using unusual free domains like .xyz or .cc. Police recommend verifying official domains such as .th or .ac.th, which are more trustworthy.
Thus, the public is urged to remember that real officials will never call to ask for passwords, OTPs, or request money transfers. If receiving suspicious calls referencing this incident, hang up and contact the institution directly via official channels.
TSD confirmed there is currently no evidence that stock holdings or securities transaction data were affected by this incident. They emphasized that affected users should not panic, as accessed data cannot be used to alter stock holdings or conduct transactions.
However, TSD advises increased caution and mindfulness during transactions, urging the public to:
Be wary of emails, SMS, or phone calls falsely claiming to be from authorities asking for personal data, passwords, or OTP codes.
Avoid clicking links, downloading files, or opening documents from unverified sources.
Do not disclose passwords, OTPs, or personal information to unknown or unverifiable contacts.
Regularly change online account passwords and avoid reusing passwords across multiple services to reduce risk of misuse (this is general cyber hygiene, not due to password leaks from this incident as no passwords were leaked).
Regularly monitor accounts and related transactions for abnormalities.
If receiving emails purportedly from TSD, ensure they come only from SETContactCenter@set.or.th and contain no links.
TSD sincerely apologizes for the incident and assures it will accelerate improvements to system security measures to restore confidence and safeguard users’ personal data to the highest standard.