Wednesday, August 5, 2026
spot_img
HomePoliticsThai PM data leak claim hits social security

Thai PM data leak claim hits social security

Tech experts alleged a security flaw in Thailand’s Social Security Office after data tied to Prime Minister Anutin was reportedly misused

BANGKOK, THAILAND – Data linked to Prime Minister Anutin Charnvirakul was allegedly misused to register him in Thailand’s Social Security Office system, intensifying criticism of the agency’s online security.

Allegations over misuse of minister’s data

Software and blockchain specialist Thanarat Kuawattanaphan, CEO of DomeCloud, made the allegations public on 1 April in a Facebook post. He claimed that the online platform of the Social Security Office (SSO) allowed users to exploit personal data traded on the internet to assume other identities and register under different names.

Thanarat said the SSO’s digital infrastructure had been developed at high cost but still contained numerous loopholes. According to his account, even people with only basic technical knowledge could allegedly imitate others or abuse their entitlements.

He wrote that after a nationwide data leak, it became apparent that the SSO website permitted registration of “any name” using personal details bought online. Critics argued that such weaknesses could facilitate identity theft and unauthorized access to sensitive records.

Screenshot suggests access to Anutin’s contribution history

To support his claims, Thanarat posted a screenshot that appeared to show an SSO interface displaying a contribution history under Anutin’s name. The image indicated a supposed payment of 750 baht per month in 2004.

He alleged that once an account was created using the prime minister’s personal information, it was then possible to access his full profile. According to his description, this access was obtained “illegally” after the registration step.

Separately, another social media user claimed to have retrieved records relating to traffic offences connected to Anutin. The user alleged that 23 suspected violations were displayed, each carrying a reported fine of 500 baht.

Call for stronger authentication standards

In response to the reported vulnerabilities, Thanarat urged Thailand to adopt the security standard AAL2 nationwide. He argued that this level of protection would better prevent identity theft in public digital services.

AAL2, or “Authenticator Assurance Level 2,” is a U.S. NIST-based framework that requires multi-factor authentication. Under this approach, users must verify their identity through at least two separate methods to increase login security.

Thanarat argued that such requirements should become the norm for state-run online portals. He suggested that relying on single-factor methods like passwords was no longer adequate for safeguarding large public databases.

Background: claims of 66 million records on Dark Web

The latest accusations followed earlier reports of a major SSO data incident raised in March by People’s Party MP Pawoot Pongvitayapanu. Pawoot said datasets on 66 million Thai citizens from the SSO database had been offered for sale on the Dark Web for 1,650 baht.

According to his account, the leaked information allegedly included first and last names, ID numbers, parental details and medical data. He criticized the handling of the incident, saying officials had fixed the issue without clearly informing the public.

Pawoot also stated that the SSO initially denied there had been any breach when the first rumours emerged. He argued that this lack of transparency undermined trust in state-managed digital platforms.

No official clarification so far

As of the latest report, there had been no formal explanation from government agencies regarding the new allegations involving Anutin’s data. Authorities had not publicly confirmed or denied that his personal details were used for an SSO registration.

There was also no official statement on the broader claims of unauthorized access to SSO or related databases. Questions remained about the scope of any past data leak and the current level of protection for citizens’ online records.

The debate has fuelled concerns over the security of state-run portals as Thailand moves more services online. Public discussion has focused on whether multi-factor authentication should be mandatory before further digital expansion of government systems.

RELATED ARTICLES

Most Popular

Recent Comments