2026.10.06
การโจมตีด้วย AI ครองอันดับ 1 ในรายงานความเสี่ยงไซเบอร์ประเทศไทยปี 2026: ไดรฟ์เก่าและข้อมูลสำรองที่บริษัทของคุณหลงลืม
รายงานการประเมินความเสี่ยงไซเบอร์แห่งชาติของประเทศไทยปี 2026 จัดให้การโจมตีที่ขับเคลื่อนด้วย AI อยู่ในอันดับสูงสุด สิ่งที่คำแนะนำเกี่ยวกับข้อมูลสำรอง ผู้ Vendor และความลับระยะยาวสื่อถึงไดรฟ์เก่าของบริษัทคุณ
แผนที่ความเสี่ยงไซเบอร์ใหม่ของไทยชู AI เป็นอันดับหนึ่ง
The National Cyber Security Agency (NCSA) has published the Thailand National Cyber Risk Assessment Report 2026 , its outlook on the cyber risks the country should watch over the next two years. Bangkok Post reported the findings on 6 October 2026.
สกมช. ได้รวบรวมคำตอบจากผู้คน 235 รายใน 134 องค์กร ซึ่งได้เลือกรายการความเสี่ยง 1,156 รายการเพื่อศึกษาอย่างละเอียดใน 20 สถานการณ์ โดยครอบคลุมตั้งแต่แรนซัมแวร์และฟิชชิ่ง ไปจนถึงการโจมตีห่วงโซ่อุปทาน ระบบควบคุมโรงงานและสาธารณูปโภค AI และควอนตัมคอมพิวติ้ง สถานการณ์ 9 ใน 20 สถานการณ์อยู่ในระดับความเสี่ยงเฉลี่ยสูง 10 สถานการณ์อยู่ในระดับปานกลาง และ 1 สถานการณ์อยู่ในระดับต่ำ จาก 1,156 รายการที่ศึกษาในเชิงลึก 576 รายการ (49.8%) ได้รับการจัดอันดับว่ามีความเสี่ยงสูง หน่วยงานระบุอย่างระมัดระวังว่านี่ไม่ได้หมายความว่าความเสี่ยงทางไซเบอร์ทั้งหมดในประเทศไทยมีความเสี่ยงสูงถึงครึ่งหนึ่ง แต่หมายความว่าครึ่งหนึ่งของรายการที่ผู้ตอบแบบสอบถามพิจารณาแล้วว่ามีความสำคัญพอที่จะตรวจสอบ
The standout result is scenario R19: AI-enabled attacks and attacks against AI systems . 160 respondents (68.1%) chose it as a risk of concern, 94 of them (40% of everyone surveyed) ranked it their number one risk, and 70% of those who assessed it rated it high. It also stood out as a prominent concern in all seven sectors covered, from finance and telecoms to transport, energy and public health. The report's point is simple: AI helps defenders, but it also helps attackers work faster, at greater scale and with more polish.
ภัยคุกคามรูปแบบเดิมยังคงอยู่ไม่ได้หายไปไหน
Alongside AI, the report says familiar threats still form the base of Thailand's risk picture: exploited software vulnerabilities, ransomware, unauthorised access, account takeover, data theft, phishing and online fraud. It also warns about a cascade effect , where one incident at a shared service provider spreads to many organisations at once.
คำแนะนำสำหรับองค์กรประกอบด้วย:
- การแยกข้อมูลสำรองออกจากระบบหลัก การทดสอบการกู้คืนข้อมูลเป็นประจำ และการแบ่งส่วนเครือข่ายเพื่อป้องกันแรนซัมแวร์
- การทำแผนผังความเกี่ยวข้องและการกำหนดข้อกำหนดด้านความปลอดภัยสำหรับผู้ให้บริการ
- การจัดทำบัญชีรายการระบบ AI พร้อมผู้รับผิดชอบที่ชัดเจน และจำกัดขอบเขตการทำงานของเครื่องมือ AI
- การทบทวนการเข้ารหัสและคีย์ปัจจุบันเพื่อเตรียมพร้อมรับมือกับภัยคุกคามควอนตัม บทสรุปภาษาไทยของ สกมช. ระบุเพิ่มเติมว่าองค์กรควรระบุข้อมูลที่ต้องเก็บรักษาเป็นความลับในระยะยาว
A week earlier, on 30 September, ThaiCERT shared a SOCRadar study (global, not Thailand-only) of malware "stealer logs" taken from infected computers. Over 90 days it found 482 organisations with exposed AI accounts or credentials. The stolen data included session cookies and API keys, which can let an attacker stay logged in even after a password change. The researchers also warned that AI chat histories can hold source code, customer data and contracts that employees have pasted in.
สิ่งนี้หมายความว่าอย่างไรสำหรับบริษัทของคุณ
None of this is a report about old hardware. But every recommendation above comes back to one question that most Thai companies cannot answer quickly: where are all the copies of our data, and which ones do we still need?
- Every backup is a copy, including the old ones. Isolated backups are good advice. But the backup drives you replaced, the NAS in the storeroom and the disks pulled from a server during an upgrade are copies too. Ransomware groups often copy data before they encrypt it and then threaten to publish it. Data you no longer keep cannot be stolen that way.
- "Encrypted" may not mean "safe forever". The NCSA is asking organisations to identify data that must stay secret for years, because today's encryption may not hold against future computing power. For a drive holding long-life secrets that is leaving your control, physical destruction settles the question.
- Laptops remember logins. Stealer logs show how much sits on an ordinary work computer: saved passwords, live sessions, API keys. A retired laptop handed on or sold "as is" can still carry all of it.
- Your disposal vendor is part of your supply chain. If the NCSA wants security requirements for service providers, that should include whoever takes away your old servers and drives. Ask for chain of custody, serial-number logging and a certificate for each device.
รายการตรวจสอบสั้นๆ ก่อนการอัปเดตฮาร์ดแวร์ครั้งถัดไป
- เพิ่มพื้นที่จัดเก็บข้อมูลที่ปลดระวางและสำรองไว้ลงในบัญชีทรัพย์สินของคุณ: ดิสก์สำรองข้อมูลเก่า, หน่วยความจำ NAS, อุปกรณ์สำรอง RAID, เซิร์ฟเวอร์ที่ปลดประจำการ และแล็ปท็อปที่รออยู่ในตู้เก็บของ
- กำหนดวันหมดอายุสำหรับชุดข้อมูลสำรองแต่ละชุด และทำลายสื่อบันทึกข้อมูลเมื่อถึงกำหนดเวลานั้นแทนที่จะเก็บไว้ "เผื่อจำเป็น"
- Before a laptop leaves the company, revoke its sessions and keys, then wipe it properly or destroy the storage. Our laptop data destruction service does either, with a certificate.
- Send loose disks for hard drive and SSD destruction , and handle rack equipment through documented server data destruction with an inventory report.
- For a full office refresh or move, treat it as one IT asset disposal project and file the certificates with your PDPA records.
เราทำลายฮาร์ดไดรฟ์และ SSD ทางกายภาพ (HDD, SSD, M.2 และ NVMe) พร้อมออกใบรับรองการทำลายข้อมูล (Certificate of Destruction) สำหรับไดรฟ์ทุกตัว โดยแสดงหมายเลขซีเรียล วิธีการ และวันที่ เราจัดการเฉพาะอุปกรณ์จัดเก็บข้อมูลเท่านั้น และไม่มีบริการทำลายเอกสารกระดาษ
Get an instant quote or call 082-797-3702 to destroy the old drives, servers and laptops your company no longer needs, so the data on them can never feed the next attack.
Sources: Bangkok Post, "AI-enabled attacks rank as top cyber risk" (6 Oct 2026), reporting the NCSA's Thailand National Cyber Risk Assessment Report 2026; NCSA's Thai-language summary of the report as carried by Thai media (5 Oct 2026); ThaiCERT, "Infostealers Target Enterprise AI Accounts, Exposing Sessions, API Keys, and Sensitive Data" (30 Sep 2026), summarising a global SOCRadar study.
บทความที่เกี่ยวข้อง
บริการทำลายฮาร์ดไดรฟ์และ SSD กรุงเทพฯ
การทำลายที่ได้รับการรับรอง ปฏิบัติตาม PDPA ในกรุงเทพฯ
Learn More