2026.10.01
Thailand's August 2026 Government Data Leak: What It Teaches About Old Systems and Retired Devices
Stolen logins, abandoned back-end systems and data kept for years: what Thailand's August 2026 government data leak shows about decommissioning servers, drives and computers.
What Happened in August 2026
In early August 2026, photos and personal data of Thai citizens, including ID card photos of the Prime Minister and cabinet ministers, were posted online. The government ordered every agency involved to investigate, and the story quickly grew.
- Stolen staff logins, not database hacks. Police said attackers did not break into databases directly. They used hijacked accounts of users who had legitimate access, pulled the data out, and sold it on the dark web, Telegram and Discord.
- Vehicle records pulled through a data-sharing link. The Department of Land Transport said its data was accessed through the system that lets government agencies look up records. One account linked to a district office ran more than 7,000 searches. Access was tightened across 63 agencies.
- Huge volumes of stolen logins. ThaiCERT found more than 16,520 files, about 5 terabytes, of stolen logins circulating on Telegram. A review of Thai domains found 221,947,958 records covering government, companies, schools, non-profits and the military.
The Government's Response
On 11 August 2026 the cabinet approved three measures proposed by the National Cyber Security Committee:
- Force password reset for staff in more than 300 departments.
- System cleansing: inspect more than 30,000 information systems within 15 days. Old or abandoned systems must have their back-end access permanently shut off, because some agencies had taken websites offline but left the systems behind them reachable.
- Multi-factor authentication for government systems, including the ThaID app.
Three Lessons for Any Organisation
1. A system you stopped using is still a risk. Turning off a website or unplugging a server does not remove the data. Until the drives are properly wiped or go through hard drive destruction, the data is still there for anyone who gets access.
2. Keeping data too long makes the leak bigger. The security researcher who raised the alarm said some of the leaked data had been kept for more than five years. Data you no longer need should be destroyed on schedule, not stored indefinitely. The PDPA requires personal data to be deleted or destroyed once it is no longer needed.
3. Logins are stolen from ordinary computers. Officials said many logins were stolen by malware on staff computers. Old office PCs and laptops often still hold saved passwords, browser sessions and cached files. When these machines are retired, sold or donated, a factory reset is not enough.
Practical Steps
- List every server, PC, laptop and drive you have retired or plan to retire.
- Shut off remote and back-end access to any system you no longer use.
- Wipe or physically destroy the storage before the hardware leaves your control.
- Get a certificate for each device, showing serial number, method and date, and keep it with your PDPA records.
We Can Help
We provide server data destruction and full IT asset disposal in Bangkok, covering servers, drives, desktops, laptops and phones, with a Certificate of Data Destruction for every device. Pickup is available, or you can ship to us from anywhere in Thailand.
Get an instant quote or call 082-797-3702.
Sources: Thai Post, 7 August 2026; Bangkok Post, 8 August 2026; Bangkok Post, 13 August 2026.
Related Articles
Server Data Destruction Service Bangkok
Certified, PDPA-compliant destruction in Bangkok.
Learn More