2026.10.01

เหตุการณ์ข้อมูลภาครัฐไทยรั่วไหล สิงหาคม 2026: บทเรียนจากระบบเก่าและอุปกรณ์ที่ปลดระวาง

ข้อมูลเข้าสู่ระบบที่ถูกขโมย ระบบหลังบ้านที่ถูกทิ้งร้าง และข้อมูลที่เก็บไว้มานานหลายปี: สิ่งที่เหตุการณ์ข้อมูลภาครัฐไทยรั่วไหลในเดือนสิงหาคม 2026 สะท้อนให้เห็นเกี่ยวกับการปลดระวางเซิร์ฟเวอร์ ไดรฟ์ และคอมพิวเตอร์

อ่านภาษาไทย

เหตุการณ์ที่เกิดขึ้นในเดือนสิงหาคม 2026

ในช่วงต้นเดือนสิงหาคม 2026 ภาพถ่ายและข้อมูลส่วนบุคคลของประชาชนไทย รวมถึงภาพถ่ายบัตรประจำตัวประชาชนของนายกรัฐมนตรีและรัฐมนตรี ได้ถูกเผยแพร่ทางออนไลน์ ทางการได้สั่งการให้ทุกหน่วยงานที่เกี่ยวข้องทำการตรวจสอบ และเรื่องราวดังกล่าวก็ขยายวงกว้างอย่างรวดเร็ว

  • Stolen staff logins, not database hacks. Police said attackers did not break into databases directly. They used hijacked accounts of users who had legitimate access, pulled the data out, and sold it on the dark web, Telegram and Discord.
  • Vehicle records pulled through a data-sharing link. The Department of Land Transport said its data was accessed through the system that lets government agencies look up records. One account linked to a district office ran more than 7,000 searches. Access was tightened across 63 agencies.
  • Huge volumes of stolen logins. ThaiCERT found more than 16,520 files, about 5 terabytes, of stolen logins circulating on Telegram. A review of Thai domains found 221,947,958 records covering government, companies, schools, non-profits and the military.

การตอบสนองจากภาครัฐ

เมื่อวันที่ 11 สิงหาคม 2026 คณะรัฐมนตรีได้อนุมัติ 3 มาตรการที่เสนอโดยคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ:

  1. Force password reset for staff in more than 300 departments.
  2. System cleansing: inspect more than 30,000 information systems within 15 days. Old or abandoned systems must have their back-end access permanently shut off, because some agencies had taken websites offline but left the systems behind them reachable.
  3. Multi-factor authentication for government systems, including the ThaID app.

3 บทเรียนสำหรับทุกองค์กร

1. A system you stopped using is still a risk. Turning off a website or unplugging a server does not remove the data. Until the drives are properly wiped or go through hard drive destruction , the data is still there for anyone who gets access.

2. Keeping data too long makes the leak bigger. The security researcher who raised the alarm said some of the leaked data had been kept for more than five years. Data you no longer need should be destroyed on schedule, not stored indefinitely. The PDPA requires personal data to be deleted or destroyed once it is no longer needed.

3. Logins are stolen from ordinary computers. Officials said many logins were stolen by malware on staff computers. Old office PCs and laptops often still hold saved passwords, browser sessions and cached files. When these machines are retired, sold or donated, a factory reset is not enough .

ขั้นตอนทางปฏิบัติ

  1. ทำรายการเซิร์ฟเวอร์ คอมพิวเตอร์ตั้งโต๊ะ แล็ปท็อป และไดรฟ์ทั้งหมดที่คุณได้ปลดระวางหรือวางแผนจะปลดระวาง
  2. ปิดการเข้าถึงระยะไกลและระบบหลังบ้านสำหรับระบบใดๆ ที่คุณไม่ได้ใช้งานแล้ว
  3. ลบข้อมูลหรือทำลายสื่อบันทึกข้อมูลทางกายภาพก่อนที่ฮาร์ดแวร์จะหลุดพ้นจากการควบคุมของคุณ
  4. รับใบรับรองสำหรับอุปกรณ์แต่ละชิ้น ซึ่งระบุหมายเลขซีเรียล วิธีการ และวันที่ โดยเก็บไว้คู่กับบันทึกตามกฎหมายคุ้มครองข้อมูลส่วนบุคคล (PDPA) ของคุณ

เราพร้อมให้ความช่วยเหลือ

We provide server data destruction and full IT asset disposal in Bangkok, covering servers, drives, desktops, laptops and phones, with a Certificate of Data Destruction for every device. Pickup is available, or you can ship to us from anywhere in Thailand.

Get an instant quote or call 082-797-3702.

Sources: Thai Post, 7 August 2026 ; Bangkok Post, 8 August 2026 ; Bangkok Post, 13 August 2026 .

บทความที่เกี่ยวข้อง

บริการทำลายข้อมูลเซิร์ฟเวอร์ กรุงเทพฯ

การทำลายที่ได้รับการรับรอง ปฏิบัติตาม PDPA ในกรุงเทพฯ

Learn More