BANGKOK, THAILAND – Thai authorities are probing unauthorised access to vehicle registration data from the Department of Land Transport. Real records of the Prime Minister and cabinet members appeared online through a closed access channel.
Investigators traced the breach to a single IP address and account used twice to log in. The access channel has been shut down while officials determine how personal data ended up in the open.
Two logins via one IP address
The DLT system itself was not directly hacked, according to preliminary findings. Sleuths tracked the access back to one IP address and an account used for two login attempts.
Authorities are keeping the IP location and technical details under wraps due to the active probe. The compromised gateway has been closed, preventing further data retrieval through that route.
PDPC calls it unauthorised access
Police Colonel Surapong Plengkham, secretary-general of the Personal Data Protection Committee, classified the incident as unauthorised access to protected computer data under Section 7 of the Computer Crime Act.
This distinguishes the case from a classic database leak. The PDPC aims to trace the data origin, the method of access, and the networks involved in illegal trading.
DLT confirms data is genuine
The Department of Land Transport confirmed the vehicle data circulating online is authentic. Officials say it is basic information that cannot be used for further transactions.
Thanarat Kuawattanaphan said the vehicle records came directly from a DLT system, not from any public or private entity linked to the department. Anyone spreading the data faces legal action, the DLT warned.
NCSA and ThaiCERT secure digital clues
Minister Chaichanok Chidchob ordered the National Cyber Security Agency to dispatch a team from the Thai Computer Emergency Response Team to the DLT. The minister also chairs the Cybersecurity Regulation Committee.
Investigators are gathering technical evidence, examining API activity, and tracing data origins through digital forensics. They are also checking systems of other agencies connected to DLT databases.
Complaint against possible data services under review
Deputy Digital Economy and Society Minister Nan Boonthida Somchai warned against using the leaked data for online crimes. The ministry has tasked the data protection committee and the NCSA with further probes.
A complaint to the Office of Investigation against Cybercrime is being examined. Publishing illegally obtained data can bring up to five years in prison, a fine of up to 100,000 baht, or both under Section 14 of the Computer Crime Act.
Discord bots sell government data
Thanarat Kuawattanaphan, managing director of DomeCloud, said illegal trade in personal data is nothing new. Around election time, voter lists were on offer, and vehicle registration data has been sold over the past three months.
Illegal operators use Discord bots that let paying customers search for data. Information on prominent individuals is often shown as proof of real datasets before buyers get further access.
Previous case hit 200,000 investors
The current leak follows the exposure of details on roughly 200,000 investors. That breach involved data from more than five million shareholder accounts at the Thailand Securities Depository Co Ltd.
The incidents have raised fresh questions about personal data protection in state and state-linked systems. The total number of people affected in the latest breach remains unclear.
Old passwords remain a weakness
Many government databases still rely on a username and password as the sole protection, according to Thanarat. Stolen login credentials or malware on an official’s computer can let attackers grab huge data sets.
Disused or outdated systems also serve as open doors. Illegal providers can use old passwords for fresh login attempts, targeted scam messages, or scanning for accounts still active.
Millions of records flagged in domain scan
A check published on June 10 matched government domains against a leaked-credential search tool and returned numerous hits. This does not prove actual access to or discovery in active government accounts.
The search tool showed 500,000 records each for the Interior and Education ministries — the maximum result count. The Labour Ministry had 359,535 records, the Health Ministry 212,460, the PM’s Office 198,984, the Defence Ministry 170,667, the Justice Ministry 151,626, and the Finance Ministry 107,456.
Face images likely from volunteer database
The release of face images of top figures does not mean the entire population’s data was exposed, investigators believe. Early clues point to a database of participants in volunteer activities.
Affected individuals are likely government officials and some previously registered students. The exact number is still being verified.
Agencies urged to adopt ThaID
More than 90 percent of passwords found in the scan are old and cannot be used on current systems, officials say. Some agencies already use ThaID or other login methods.
Thanarat recommends shutting down unnecessary systems and auditing all remaining databases. ThaID should be used as additional authentication, not a standalone fix. Adding ThaID logins could cut system attacks by roughly 90 percent, but identity-check capacity must grow to keep the system stable under high demand.
