
General articles are free for 24 hours after publish.
No Financial Losses from TSD Portal Data Leak, SET Assures
Thailand Securities Depository (TSD) reported no financial losses after personal data of approximately 200,000 investors was accessed without authorization via its Investor Portal. The Stock Exchange of Thailand (SET) stated a coding flaw, not a backend breach, was exploited, compromising personal details but not financial holdings or credentials.
Hackers exploited hidden coding flaw PUBLISHED : 29 Jul 2026 at 05:12 NEWSPAPER SECTION: News WRITER: Nuntawun Polkuamdee No financial losses have been detected after personal information belonging to about 200,000 investors was accessed without authorisation through Thailand Securities Depository Co Ltd's (TSD) Investor Portal website, the Stock Exchange of Thailand's (SET) subsidiary said on Tuesday. The investigation found no evidence that securities holdings, trading records, usernames or passwords had been compromised following the exploitation of a software vulnerability, TSD executives said. Suspicious activity was first detected on Saturday evening, with unauthorised access confirmed the following morning. The incident affected around 4% of the approximately 5 million shareholder records maintained in the system. TSD managing director Pichaya Chomchaiya said the incident was not caused by a direct breach of the company's backend infrastructure but stemmed from a coding flaw within the Investor Portal's User Profile page. A legitimate user successfully logged in to the system before manipulating their user ID on the profile page. Due to insufficient validation in the application's code, the modified ID enabled the system to retrieve profile information belonging to other users. By repeatedly changing the ID, the individual was able to access personal data from a large number of investor accounts. The compromised information includes investors' names, dates of birth, national identification numbers, addresses, telephone numbers, email addresses, brokerage firm names, securities account numbers, bank names and partial bank account details. However, Ms Pichaya emphasised that investors' securities holdings, portfolio values, transaction histories, usernames and passwords were not exposed, and there is currently no indication of unauthorised financial transactions resulting from the incident. TSD said it immediately closed the vulnerable access point, corrected the defective code, filed a complaint with the Cyber Crime Investigation Bureau (CCIB), and informed regulators, securities firms and commercial banks to enhance their monitoring of affected accounts. The company has also begun notifying around 200,000 affected investors via SMS and email while operating SET contact centre services, including during weekends, to answer inquiries. TSD said it will consider providing appropriate assistance if any investor later suffers damage linked to the incident. Thirapun Sanpakit, the SET's chief technology officer, said the exchange is implementing broader cybersecurity enhancements. The measures include deploying AI to scan source code across the SET Group's systems for hidden vulnerabilities, strengthening identity verification procedures, expanding penetration testing by independent cybersecurity specialists, and gradually migrating legacy web-based services that have been in operation for more than five years to newer, more secure technology platforms. "The leaked information alone cannot be used to conduct financial transactions unless victims are deceived into following fraudulent instructions," said SET president Asadej Kongsiri.
Original source
Bangkok Post