
Anudit, Deputy Leader of the Kla Party, emphasizes that the leakage of citizen data is a national security threat. He urges the government to swiftly close vulnerabilities, protect whistleblowers, and overhaul the national cyber budget system.
On 6 August 2026, Air Commodore Anudit Nakornthap, Deputy Leader of the Kla Party and former Minister of Information and Communication Technology, addressed the case where personal data of the Prime Minister, ministers, senior officials, and citizens was leaked and claimed to be accessible or sold through illegal channels. He said this is not just a matter concerning personal data of prominent individuals but a warning sign that all citizens' data is at risk.
Air Commodore Anudit said that although the government initially explained that the recent incident might not be a direct "hack" but access through the same user account and IP address, this does not lessen the problem. In cybersecurity terms, stealing access rights, unauthorized use of privileged accounts, or using insiders’ rights are data breaches as dangerous as system intrusions and sometimes even harder to detect.
“The key questions are not just whether it was a hack or not, but who accessed what data, why data was extracted, when the system detected it, and how much data was taken.”
This problem is directly linked to damages caused by call center scams and online crimes. According to the Royal Thai Police, from March 2022 to the end of 2024, 773,118 online cases were reported with damages totaling about 79.569 billion baht, and from 1 January 2025 to 12 April 2026, there were another 412,938 cases with damages of approximately 30.647 billion baht.
Combining these non-overlapping periods, Thailand has suffered at least 110 billion baht in reported online crime damages over about four years, excluding unreported victims, business losses, recovery costs, and psychological impacts on citizens. In just the first four months of 2026, there were 121,921 online cases with damages of 7.48 billion baht, averaging about 62 million baht daily. These figures show that merely warning people “not to be deceived” is insufficient if the government still allows citizens’ real data to flow as raw material to criminals.
The reason scammers still succeed daily despite widespread warnings is that scams are no longer random calls without data. Criminals can identify names, addresses, vehicles owned, affiliated organizations, and family member details, then combine these with well-trained speech techniques to make fabricated stories appear credible and relevant to victims’ real lives.
However, it should not be concluded that all leaked data originates from government databases or only from the dark web; it may come from multiple agencies, private contractors, official API accounts connected with each other, or multiple old datasets combined. What the government must do is verify the sources using digital forensics and disclose the facts rather than deny responsibility before completing investigations.
The “Cut Down Scam 2” operation by the Cyber Security Center (CSC) and the Crime Investigation Bureau (CIB) last June provided evidence that the data trading market is linked to crime. Officials arrested nine suspects, searched 22 locations, seized over 9 million personal records, and found connections to 13,677 online cases with damages over 2.008 billion baht. Personal data is thus not something “useless” but a key raw material for the scammer industry.
Air Commodore Anudit proposed that the government take urgent action in three phases as follows:
Urgent phase: isolate high-risk systems from networks, preserve all evidence and logs, revoke accounts, passwords, tokens, and API keys that might be exploited, enforce multi-factor authentication (MFA), audit the volume and types of affected data, notify the Cyber Security Center within the 72-hour legal timeframe, promptly inform data owners if there is high risk, and provide channels for citizens to check if they are affected and how to protect themselves.
Medium term: the government must audit all databases, APIs, user accounts, connected agencies, contractors, and subcontractors; enforce the principle of least privilege limiting access rights strictly to what is necessary; set rate limits and alert systems for abnormal data queries; integrate logs into Security Operations Centers (SOC) or Managed Detection and Response (MDR) systems for shared visibility; and have independent experts conduct forensic analysis before publicly releasing summary reports.
Long term: adjust government system architecture toward Zero Trust, reduce unnecessary data collection, review data retention periods, conduct red team and penetration tests by independent experts, and establish a Coordinated Vulnerability Disclosure policy with clear channels for reporting vulnerabilities and protections for good-faith whistleblowers who do not seek benefits or disclose excessive information.
Regarding the case of Thanarat Kuawatthanaphan, whom the Department of Provincial Administration reported to police in April 2026 following allegations about voter data of approximately 53 million entries, Air Commodore Anudit said the justice system must consider all facts thoroughly and fairly, clearly distinguishing between hackers, thieves, sellers, buyers, those who misuse data for crimes, and good-faith whistleblowers who detect risks and issue warnings.
“I do not mean that anyone can disclose personal data without limits. If data is excessively disclosed, legal checks must follow. However, the state should not respond to whistleblowers with immediate legal action because if those who find vulnerabilities risk lawsuits, who then will dare to help the state warn about threats?”
Air Commodore Anudit added that every ministry receives significant budgets annually for cybersecurity systems, but Thailand lacks a transparent overview disclosing to the public how much budget is spent, how much is spent on redundant systems, which systems are connected or exchange data, and whether security outcomes have truly improved.
The government should compile and disclose cyber budgets for at least the past three years, examine overlapping projects, contractors, scopes of work, and actual test results, and shift performance indicators from the number of devices or software purchased to metrics such as detection time, incident control time, recovery capability, and damage reduction.
“If the government spends a large budget every year but citizens’ data continues to leak repeatedly, systems cannot detect abnormalities by themselves, and evidence must wait for outsiders to reveal, citizens have the right to question whether those budgets are genuinely used to ensure security or just for segmented purchases benefiting certain vendors, leaving citizens exposed to risks.”
Air Commodore Anudit called on the Prime Minister to designate this incident as a national cybersecurity event, establish a review committee including independent experts, publicly disclose initial factual reports within 30 days, and release remedial plans with indicators within 90 days. The review should cover data-owning agencies, connected agencies, contractors, and those who buy and sell data equally.
“Cybersecurity is not achieved by covering up news, shutting down websites, or silencing whistleblowers but through accepting reality, preserving evidence, responsible disclosure, systematic correction, and holding those responsible accountable to the public.”