Skip to content
Telecom

True customers’ identity records exposed in data leak

By Aiko TanakaThailand
1 min read
thailand true mobile telecom
thailand true mobile telecom
In this article (5)

Thailand’s True Corp has fixed a data leak involving the exposure of identity records on up to around 45,000 of its customers.

Security researcher Niall Merrigan discovered personal data on customers of True Corp’s e-commerce subsidiary iTrueMart (now WeMall) stored in a public-facing Amazon S3 bucket in March.

The 32GB data cache included 45,736 files, consisting mainly of JPG and PDF scans of identity documents including scanned ID cards, drivers licenses and possibly passports.

In a blog post, Merrigan said he informed True Corp’s mobile unit True Move H about the breach on March 10, but the company took no action until he went to the media in early April. The files were finally made private on April 12.

Merrigan indicated that True Corp seems to be misrepresenting the incident as a hack, but there was no security on the data bucket and anybody could have found and downloaded all the files.

Telecoms regulator NBTC is investigating the incident, and may impose penalties on True Corp for exposing customer information. The stored identity records may have been collected as part of the Thai government’s mandatory SIM registration scheme, which has already been a target of identity thieves and has been opposed by privacy advocates.

Questions & Answers

Q.

What kind of data was exposed in the True Corp leak?

A.

The data cache, amounting to 32GB, mainly contained JPG and PDF scans of identity documents. These included scanned ID cards, drivers' licences, and potentially passports belonging to customers.

Q.

When was True Corp first notified about the data breach?

A.

Security researcher Niall Merrigan informed True Corp's mobile unit, True Move H, about the breach on March 10. However, the company did not take action until he contacted the media.

Q.

How did the data become exposed?

A.

The data was stored in a public-facing Amazon S3 bucket without any security. This meant anyone could have found and downloaded all the files, as it was not a hack.

Q.

Is True Corp facing any consequences for this incident?

A.

The telecoms regulator, NBTC, is currently investigating the incident. It is possible they may impose penalties on True Corp for exposing its customers' information.

Reader pulse

True Corp's handling of this data leak was:

21,922 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready