
"Phawut-Isariya," People's Party MPs, propose five approaches to upgrade cybersecurity systems and minimize the risk of future personal data leaks. They recommend that agencies detecting vulnerabilities immediately enforce password resets to prevent unauthorized system access.
At 10:00 a.m. on 11 Aug 2026 GMT+7, at the press conference room on the first floor of the Parliament building, Mr. Isariya Pairipairit together with Mr. Phawut Pongwitthayaphanu, members of the House of Representatives from the People's Party, jointly held a press conference regarding the leakage of personal data from government agencies.
Mr. Isariya Pairipairit stated that the recent leakage of personal data from government agencies, including images and data of the Prime Minister, may not be due to direct hacking through system vulnerabilities but rather data leaks related to identity verification or compromised passwords. This partly results from the government's over 1,000 separate IT systems, each developed and managed independently by various agencies. Many systems have been in use for over 10 years with insufficient security measures. Some older systems rely solely on usernames and passwords without proper access level controls. Coupled with insecure password practices such as sharing passwords or using easily guessable ones, important government data faces significant risks. Some data may have leaked long ago and been used to access interconnected systems sequentially. The concern is that leaked data includes highly sensitive information like civil registration and high-resolution photos used for national ID cards, which hackers, scammers, or malicious actors could exploit to impersonate and verify identities with government systems. Once leaked, it is nearly impossible to recover such data, making urgent system improvements necessary to prevent repeated unauthorized access. He proposed the following solutions.
1. Agencies that detect password leakage risks should immediately enforce password resets for all users and discontinue use of old passwords to prevent malicious reuse of leaked credentials.
2. The National Cybersecurity Committee (NCC) should consolidate all government IT systems and promptly conduct security audits, including reviewing access rights of officials, former executives, and contracted system developers. Progress should be disclosed via a public dashboard for citizen monitoring.
3. The Personal Data Protection Committee (PDPC) should rigorously enforce the Personal Data Protection Act (PDPA) on government agencies as strictly as on the private sector. Even if leaks are unintentional, negligence, flawed system design, or inadequate security measures must hold agencies and related executives accountable, with urgent upgrades to data protection standards and effectiveness.
Mr. Phawut Pongwitthayaphanu proposed medium- and long-term solutions as follows.
1. The Ministry of Digital Economy and Society should collaborate with the NCC to establish centralized standards for system management and identity verification across government agencies, covering password use, OTP codes, and authentication methods, ensuring uniform security standards.
2. Transition from relying solely on usernames and passwords to multi-factor authentication systems, such as OTP codes or authentication apps, to enhance security and prevent unauthorized access even if credentials are compromised.
3. Reduce repeated requests for sensitive personal information like ID card numbers across systems by utilizing the government's central digital identity verification system, such as ThaID, to minimize scattered personal data storage and lower leakage risks.
4. Implement a centralized logging system to record user access details—who logged in, when, and what actions were taken—while preventing tampering or deletion, enabling effective cybersecurity incident tracking and audits.
5. Promote continuous vulnerability assessments by adopting a “Bug Bounty” program that rewards individuals who discover and report security flaws. Establish clear channels and criteria to encourage experts and citizens to participate in system audits without fear of being perceived as offenders.
Since personal data collected by government agencies is highly sensitive and critical, it is essential to urgently raise standards in technology, management, and auditing to strengthen government cybersecurity and reduce the risk of personal data leaks in the future.