
The Prime Minister has ordered all agencies to promptly investigate and establish internal committees to find the source of the personal data leak, emphasizing that such incidents should not happen. He is pushing for all units to implement multi-factor authentication systems within 30 days.
On 6 Aug 2026 GMT+7, Ms. Ratchada Thanadirek, spokesperson for the Prime Minister's Office, disclosed that after personal data and images were shared on social media, Prime Minister Anutin Charnvirakul ordered all relevant agencies to urgently verify the facts and set up internal investigation committees to identify the cause and those responsible. He stressed that incidents like this should not occur and must be used as an opportunity to raise security standards for government data systems.
Ms. Ratchada said the Ministry of Digital Economy and Society reported that preliminary checks found no direct breach of government databases. They have closed related access points and are accelerating digital forensic examinations to determine the cause and identify those involved.
The Ministry of Transport has suspended user accounts showing suspicious activity and ordered password changes across all agencies connected to the Department of Land Transport. They have forwarded information to the Technology Crime Suppression Division (TCSD) for investigation.
Meanwhile, the Ministry of Interior and the Department of Provincial Administration are investigating access routes to the data. The Department of Provincial Administration confirmed no leakage from the main civil registration database has been found.
The National Cybersecurity Committee (NCSC) is expediting inspections and evaluations of information systems across approximately 300 government departments nationwide within 30 days. It is also promoting mandatory use of multi-factor authentication (MFA) as a standard to enhance government data security, reduce risks of unauthorized access, and prevent recurrence of similar incidents.
Ms. Ratchada stated the government does not conceal problems or deny responsibility before investigations conclude and is ready to adopt beneficial recommendations, including closing security loopholes, verifying data access rights, protecting whistleblowers acting in good faith, and evaluating cybersecurity budget effectiveness, to ensure genuine public protection.