2026.10.08

Hackers Breached a Travel Giant's Thai File Server, and the Passport Data Went Back to 2017

On 7 October 2026, H.I.S. said a file server at its Thai subsidiary was breached, exposing passport details for up to 627 travellers going back to 2017. Sorting through years of mixed files took almost ten months. Here is what Thai companies should learn about old data and retired servers.

อ่านภาษาไทย

An Alarm on a File Server in Thailand

On 7 October 2026, Japanese travel company H.I.S. Co. announced that a file server at its Thai subsidiary, H.I.S. Tours Co., Ltd., had been accessed by an outside party, and that passport details for up to 627 customers may have been taken. Kyodo News and the Japanese travel trade site Travel Vision reported the announcement the same day.

According to the company's own notice, intrusion-detection software on the server raised an alert on 11 December 2025. Staff disconnected the server from the network and restricted outside access. An investigation with outside experts then found that some of the data on it may have been pulled out.

What Was on the Server

The records at risk belong to customers who travelled to Thailand with H.I.S. in 2017, in 2019 to 2020 and in 2024 to 2025. They include names in Roman letters, the name in the signature field, gender, date of birth, passport number and expiry date, plus allergy information. In an update the same evening, the company said the people affected are group-tour customers from those years and individual travellers who left Japan in November 2024, stayed at the Pullman hotel in Bangkok and joined the Chiang Mai lantern festival. H.I.S. says phone numbers, addresses, email addresses and credit card details were not included, and it is contacting the customers it can identify.

Why It Took Almost Ten Months

For any business, the most useful part of the notice is the timeline. On 29 December 2025 the company confirmed that the server held personal data collected in Japan and reported it to Japan's Personal Information Protection Commission and to JIPDEC, a Japanese privacy body. On 24 February 2026, outside experts found passport data for up to 627 people, and H.I.S. decided to check every file on the server.

That check is what took until October. H.I.S. explains that the server held a large amount of data unrelated to personal information, such as accounting records, in many different file formats and conditions. Automated searching did not work, so files had to be examined and cross-checked one by one, partly by hand. The company says it will strengthen security at its overseas operations and tighten head-office monitoring of systems.

What This Means for Your Company

H.I.S. spotted the intrusion and cut the server off quickly. The hard part came afterwards: nobody could say quickly what was on the server, because years of passport data sat mixed in with accounting files. Plenty of Thai companies have the same kind of shared drive. Travel agents, hotels, HR teams, clinics, schools and property firms routinely collect passport copies and Thai ID card copies, and those files tend to stay put long after the trip, the booking or the contract is over.

  • Old data is still breach data. Travel records from 2017 had little use left by late 2025, but they were still there to be taken. Data you have already destroyed cannot leak, and you do not have to hunt for it after an incident.
  • The PDPA expects a deletion system, not just a password. Section 37 of Thailand's Personal Data Protection Act requires data controllers to have a system for erasing or destroying personal data once its retention period ends or it is no longer needed for its purpose. It also requires them to notify the PDPC Office of a breach without delay, and within 72 hours where feasible, unless the breach is unlikely to put people at risk. That deadline is very hard to meet when you do not know what a server holds. Our guide covers the PDPA data destruction requirements.
  • Retired hardware carries the whole history. When a file server is replaced, the data is usually copied across to the new system and the old disks keep their own complete copy. If those disks are stored, resold or handed to an unknown recycler, the risk has simply moved.
  • Branches and subsidiaries drift. H.I.S.'s own fix points at overseas security and head-office monitoring. In any group with branches, local file servers and spare drives are the assets most likely to fall outside central records.

A Simple Clean-Up Plan

  1. List every file server, NAS and shared drive, including ones at branches and in storerooms, and name an owner for each.
  2. Find the folders of passport scans, ID card copies and customer lists, set a retention period for each type, and delete what has passed it.
  3. When you move to new hardware or to the cloud, do not keep the old machine "just in case". Book documented server data destruction with serial numbers logged and a certificate for each unit.
  4. Send loose and spare disks for hard drive and SSD destruction, and treat a full office refresh as one IT asset disposal project, filing the certificates with your PDPA records.

For server jobs we collect from your Bangkok office, log serial numbers on collection, keep a full chain of custody through physical destruction, and issue a Certificate of Data Destruction for each server (serial number, method and date) plus an inventory report. Photo and video evidence is available. We handle devices only; we do not shred paper.

Get an instant quote or call 082-797-3702 to destroy the old servers and drives your company no longer needs, so years of customer passports and ID copies are not left sitting there for the next intruder.

Sources: H.I.S. Co., Ltd., customer notice on unauthorised access to a subsidiary's file server (Japanese, 7 Oct 2026, updated 19:30 JST the same day); Kyodo News, "Japanese travel agency H.I.S. reports possible passport data leak" (7 Oct 2026); Travel Vision (7 Oct 2026); Thailand's Personal Data Protection Act B.E. 2562 (2019), Section 37.

Related Articles

Server Data Destruction Service Bangkok

Certified, PDPA-compliant destruction in Bangkok.

Learn More