Thairath Online
Thairath Online

Earth Thanarat Provides Cyber Police with Information on Personal Data Leak Affecting 19 Ministries

Crime06 Aug 2026 15:51 GMT+7

Share

Earth Thanarat Provides Cyber Police with Information on Personal Data Leak Affecting 19 Ministries

Earth Thanarat provided information to cyber police, revealing a widespread personal data leak covering all 19 ministries, and confirmed no political intent. The Cyber Crime Division 1 chief said Thanarat was questioned as a witness, with no legal action taken yet.

At 1:00 p.m. on 6 Aug 2026 at the Cyber Crime Investigation Division 1 headquarters (CCID1), Government Complex, Chaeng Watthana, Laksi District, Bangkok, Mr. Thanarat Kuawattanapan, CEO of Dome Cloud and software and technology expert, met with Pol. Maj. Gen. Siriwat Deepho, commander of CCID1, Pol. Col. Ratchatchok Leewanichakun, deputy commander, Pol. Col. Runglert Kanthajan, chief of division 1, and investigators to provide information regarding personal data leaks including ID card photos, vehicle registration data, and information of prime ministers, ministers, and many citizens.
     
Thanarat said he had previously provided information to police by phone and was surprised to be called for a meeting, fearing possible legal action. He emphasized that the data disclosure aimed to warn relevant agencies after multiple notifications through the digital commission and government bodies went unaddressed for over two months, until new leaks with facial photos were found.




He decided to publicize data of high-ranking individuals to raise awareness, denying any political motive. The leak expanded widely, covering all 19 ministries and the Prime Minister's Office, especially the Ministry of Interior and Ministry of Education, totaling 20 agencies. He noted a website collected leaked passwords for sale, and he had officially reported vulnerabilities to three agencies: the National Health Security Office (NHSO) and two private sector organizations.
      
Currently, personal data of over 500,000 Thais have leaked, mostly due to officials' passwords compromised by malware-infected computers, not direct system hacks. Criminals collect and sell these passwords; buyers test access, and if valuable data is found, they create APIs to extract and sell the information.

Regarding NHSO data, large amounts of sensitive information are accessible, including ID numbers, household registration data, parents' ID numbers, enabling family tree mapping, as well as vehicle registration and facial photos. Thanarat questioned the data protection standards of government agencies, noting the problem is not only weak passwords but also excessive data retention, with some leaked data stored for over five years.
     



Thanarat added that high-profile individuals’ data is often used to increase value in illicit sales. This issue has persisted for a long time, so he urged all agencies to strengthen personal data protection measures and strictly enforce laws beyond merely closing system vulnerabilities.
     
When asked about Digital Economy and Society Minister Chaiyachon Chidchob’s view that there might be political implications, Thanarat said he understood such perceptions because the data involved personnel from agencies under the Bhumjaithai Party’s oversight, but he insisted there was no political intent. Regarding the Department of Provincial Administration’s intention to take legal action, he said he is prepared to comply with the law and has faced similar complaints previously related to voter data leaks.


The issue began when Thanarat investigated the election card system and received anonymous information about the buying and selling of voter registration books. This led to further investigation revealing data from multiple agencies being sold, prompting him to disclose the problem publicly and push for serious corrective action.
     
Pol. Maj. Gen. Siriwat said the Digital Economy and Society Ministry, Department of Provincial Administration, and Ministry of Interior have filed complaints with CCID1 to prosecute those responsible for the data leaks, without naming individuals. The summons of Mr. Earth today was solely for witness testimony, with no charges filed. Regarding the method of attack,

investigation shows criminals did not hack databases directly but compromised user accounts with system access rights, then used these accounts to extract data. They displayed high-profile individuals’ data to prove the leaks and sold the information via Dark Web, Telegram, or Discord. The Royal Thai Police have established a task force with PDPC, the National Anti-Corruption Commission, and related agencies to examine log files and access routes and to determine if account owners were hacked or complicit.
     
Cyber police are particularly concerned that personal data may be exploited by call center gangs to target victims with precise details, making scams more believable and victims more susceptible.




Pol. Maj. Gen. Siriwat warned the public that if they receive calls from people claiming to represent agencies and who know personal details, they should not trust or follow instructions immediately. Instead, they should hang up and directly call the agency to verify, to avoid falling victim to scams.
      
When asked which agency is primarily responsible for prevention, Pol. Maj. Gen. Siriwat said several agencies share responsibility, including the National Anti-Corruption Commission and the Cyber Security Agency. Cyber police’s role is to enforce laws, investigate, and apprehend offenders after incidents occur.