2026.10.06

AI Attacks Top Thailand's 2026 Cyber Risk Report: The Old Drives and Backups Your Company Forgot

Thailand's National Cyber Risk Assessment Report 2026 puts AI-enabled attacks at the top. What its advice on backups, vendors and long-term secrets means for your company's old drives.

อ่านภาษาไทย

Thailand's New Cyber Risk Map Puts AI at the Top

The National Cyber Security Agency (NCSA) has published the Thailand National Cyber Risk Assessment Report 2026, its outlook on the cyber risks the country should watch over the next two years. Bangkok Post reported the findings on 6 October 2026.

The NCSA gathered answers from 235 people at 134 organisations, who picked out 1,156 risk items for closer study across 20 scenarios. These run from ransomware and phishing to supply-chain attacks, factory and utility control systems, AI and quantum computing. Nine of the 20 scenarios came out at a high average risk level, ten at medium and one at low. Of the 1,156 items studied in depth, 576 (49.8%) were rated high. The agency is careful to point out that this does not mean half of all cyber risk in Thailand is high. It means half of the items respondents considered important enough to examine.

The standout result is scenario R19: AI-enabled attacks and attacks against AI systems. 160 respondents (68.1%) chose it as a risk of concern, 94 of them (40% of everyone surveyed) ranked it their number one risk, and 70% of those who assessed it rated it high. It also stood out as a prominent concern in all seven sectors covered, from finance and telecoms to transport, energy and public health. The report's point is simple: AI helps defenders, but it also helps attackers work faster, at greater scale and with more polish.

The Old Threats Have Not Gone Anywhere

Alongside AI, the report says familiar threats still form the base of Thailand's risk picture: exploited software vulnerabilities, ransomware, unauthorised access, account takeover, data theft, phishing and online fraud. It also warns about a cascade effect, where one incident at a shared service provider spreads to many organisations at once.

Its recommendations for organisations include:

  • Keeping backups isolated from main systems, testing data recovery regularly and segmenting networks against ransomware.
  • Mapping dependencies and setting security requirements for service providers.
  • Keeping an inventory of AI systems with clear owners, and limiting what AI tools are allowed to do.
  • Reviewing current encryption and keys to prepare for quantum threats. NCSA's Thai-language summary adds that organisations should identify data that must stay confidential for the long term.

A week earlier, on 30 September, ThaiCERT shared a SOCRadar study (global, not Thailand-only) of malware "stealer logs" taken from infected computers. Over 90 days it found 482 organisations with exposed AI accounts or credentials. The stolen data included session cookies and API keys, which can let an attacker stay logged in even after a password change. The researchers also warned that AI chat histories can hold source code, customer data and contracts that employees have pasted in.

What This Means for Your Company

None of this is a report about old hardware. But every recommendation above comes back to one question that most Thai companies cannot answer quickly: where are all the copies of our data, and which ones do we still need?

  • Every backup is a copy, including the old ones. Isolated backups are good advice. But the backup drives you replaced, the NAS in the storeroom and the disks pulled from a server during an upgrade are copies too. Ransomware groups often copy data before they encrypt it and then threaten to publish it. Data you no longer keep cannot be stolen that way.
  • "Encrypted" may not mean "safe forever". The NCSA is asking organisations to identify data that must stay secret for years, because today's encryption may not hold against future computing power. For a drive holding long-life secrets that is leaving your control, physical destruction settles the question.
  • Laptops remember logins. Stealer logs show how much sits on an ordinary work computer: saved passwords, live sessions, API keys. A retired laptop handed on or sold "as is" can still carry all of it.
  • Your disposal vendor is part of your supply chain. If the NCSA wants security requirements for service providers, that should include whoever takes away your old servers and drives. Ask for chain of custody, serial-number logging and a certificate for each device.

A Short Checklist Before Your Next Hardware Refresh

  1. Add retired and spare storage to your asset inventory: old backup disks, NAS units, RAID spares, decommissioned servers and laptops waiting in a cupboard.
  2. Set an end-of-life date for every backup set, and destroy the media when that date comes instead of keeping it "just in case".
  3. Before a laptop leaves the company, revoke its sessions and keys, then wipe it properly or destroy the storage. Our laptop data destruction service does either, with a certificate.
  4. Send loose disks for hard drive and SSD destruction, and handle rack equipment through documented server data destruction with an inventory report.
  5. For a full office refresh or move, treat it as one IT asset disposal project and file the certificates with your PDPA records.

We physically destroy hard drives and SSDs (HDD, SSD, M.2 and NVMe) and issue a Certificate of Destruction for every drive, showing serial number, method and date. We handle devices only; we do not shred paper.

Get an instant quote or call 082-797-3702 to destroy the old drives, servers and laptops your company no longer needs, so the data on them can never feed the next attack.

Sources: Bangkok Post, "AI-enabled attacks rank as top cyber risk" (6 Oct 2026), reporting the NCSA's Thailand National Cyber Risk Assessment Report 2026; NCSA's Thai-language summary of the report as carried by Thai media (5 Oct 2026); ThaiCERT, "Infostealers Target Enterprise AI Accounts, Exposing Sessions, API Keys, and Sensitive Data" (30 Sep 2026), summarising a global SOCRadar study.

Related Articles

Hard Drive and SSD Destruction Service Bangkok

Certified, PDPA-compliant destruction in Bangkok.

Learn More