9near.org leak: personal data of ~55 million Thais exposed for sale
In March 2023, a threat actor using the alias '9Near' claimed to possess personal data of approximately 55 million Thai citizens — close to the entire adult population — and listed it for sale on a dark-web forum. The dataset reportedly included full names, Thai national ID numbers, dates of birth, and phone numbers. The leak prompted intervention from Thailand's Ministry of Digital Economy and Society (MDES) and the National Cyber Security Agency (NCSA), and the 9near.org site was taken offline within days. Investigators traced the source to a government-adjacent system rather than a single private breach, highlighting how data aggregated across public services becomes a single point of catastrophic failure when access controls fail.
The incident became a defining PDPA test case. While PDPA had been in force since June 2022, this was the first nationally visible breach to trigger public scrutiny of data-controller obligations: 72-hour notification, evidence preservation, and impact assessment. Several enterprises holding similar datasets quietly audited their own access logs in the weeks that followed.
What this means for your business
Audit every system that holds aggregated personal data — especially shared APIs and reporting databases. Assume external attackers know which datasets exist; the question is who can read them and whether you would notice exfiltration in time.
