Thairath Online
Thairath Online

Personal Data of Prime Minister and Ministers Leaked, Exposing Government System Weaknesses Doubts Raised Over Cybersecurity Budget Effectiveness

Interview05 Aug 2026 19:57 GMT+7

Share

Personal Data of Prime Minister and Ministers Leaked, Exposing Government System Weaknesses Doubts Raised Over Cybersecurity Budget Effectiveness

Personal data of the Prime Minister and ministers has been widely leaked. A big data expert points out this reflects lax government systems that allow scammers to misuse the information, raising questions about the effectiveness of the hundreds of millions baht allocated to cybersecurity.

In the case where Mr. Thanarat Kueawatthanapan, a private sector IT expert, posted a warning about personal data leaks, revealing data and frontal photos from national ID cards of Mr. Anutin Charnvirakul, the Prime Minister, senior officials from the Ministry of Interior, and several other ministers, sparking criticism about the security of personal data held by government agencies.

Today (5 Aug 2026), the Prime Minister said the frontal photo leaked from the ID card is genuine and was taken long ago. He has ordered relevant agencies to urgently inspect their security systems.

Meanwhile, Mr. Chaiyachonok Chidchob, Minister of Digital Economy and Society, revealed initially it was not a hacking incident. The leak originated from a single IP address from one location, with two login attempts using an account. The system has now been shut down. Regarding speculation that politics was involved in the leak, Chaiyachonok said the behavior observed makes it highly possible but no definitive conclusion can be drawn yet. He urged waiting for investigation results and that relevant agencies will clarify the behavior in due course.

Thairath Online's special news team inquired about this matter with Dr. Thamthee Sukchotirat, known as Dr. Ruebin, a big data expert. He revealed that Mr. Thanarat discovered a critical vulnerability leading to the leakage of high-resolution personal data from ID cards. The leaked data enables scammers to easily commit fraud, impacting citizen security through data forgery, fraudulent service sign-ups, or scams.

Conversely, when such data leaks occur, government agencies violating PDPA regulations often fail to act appropriately. For example, they may deny issues, threaten those who find system vulnerabilities, provide false information to the public, claim to have filed police reports when they might have reported the finder of the vulnerability, announce fixes prematurely, or shift blame to other agencies accessing government databases as the source of the leak.

Dr. Thamthee observes that the Personal Data Protection Act (PDPA) is a good law based on the global standard GDPR from the European Union but requires stricter enforcement.

When government agencies err, there are rarely serious penalties or fines. So far, only the Election Commission has been fined. This lack of consequences means other state agencies holding citizens' data do not fear repercussions, fail to improve systems seriously, and neglect personal data security, resulting in leaks despite substantial cybersecurity budgets allocated to various government projects, with development costs lowered since AI adoption.

“Software development that once cost one million baht can now be done with AI for as little as ten thousand baht. But ensuring security and preventing data leaks is the crucial matter. This raises the question: Are the hundreds of millions baht in government cybersecurity budgets truly being used effectively, given that data breaches still occur?”

Dr. Thamthee emphasizes that beyond system security improvements, legislation should protect those who discover vulnerabilities and report them in good faith—white hat hackers—from threats or lawsuits. AI tools could help identify system weaknesses, encouraging government agencies to seriously enhance their security. Otherwise, vulnerabilities will increase avenues for criminals to access citizens' personal data, causing harm.

ดร.ธรรม์ธีร์ สุกโชติรัตน์

Government agencies collect data both separately and collectively across multiple units, depending on project budgets funded by taxpayers. Each project has system developers, server administrators, and purchases cybersecurity services from various providers.

Dr. Thamthee explained that the leaked data likely reaches scammers through various means: some individuals hack government personal data to sell it on dark markets domestically and abroad, where scammers buy it to commit fraud, extract information to intimidate, invade privacy, or impersonate citizens to sign up for services.

Most recently, on 5 Aug 2026, Mr. Nithikorn Boonyakulcharoen (Palm), a former party-list MP candidate for the People's Party, posted four proposals to protect citizens' personal data held by government agencies:

1. Upgrade user authentication for government systems to Digital ID (IAL2) Replace username/password with IAL2-level Digital ID authentication, such as ThaiD or equivalent standards, ensuring genuine authorized access.

2. Change project management so the state owns the systems and data Reduce reliance on external contractors directly accessing citizens' data. Government agencies should control access rights, allowing contractors access only to necessary data for their work.

3. Enforce least privilege access and zero trust in all systems Ensure employees access only data essential to their duties, with clear permissions, logging of all access, and anomaly detection systems to reduce risks from insiders and outsiders.

4. Citizens should be able to audit access history of their data Citizens must have the right to check which agencies or officials accessed their data, when, and why, with complaint channels for improper access, promoting transparency and accountability in government data use.

Mr. Nithikorn concluded by reminding that hacking or misusing personal data violates the Computer Crime Act and PDPA. He urged against such acts, noting that Thailand's National Cybersecurity Agency (NCSA) and Personal Data Protection Committee Office (PDPC) are ready to enforce the law.