True Move told to consider compensation over data leak

In this article (5)
Thai telecoms regulator NBTC has instructed mobile operator True Move H to assess the impact of its recent personal data leak and offer compensation to any affected customers.
The regulator also plans to conduct a formal investigation into the incident and consider imposing punishments, and issue a letter demanding that mobile operators take appropriate steps to prevent similar breaches in the future.
A security researcher recently revealed that the identity documents of up to 45,736 customers of True subsidiary iTrueMart had been exposed by being stored in a publicly-accessible Amazon S3 data bucket. The company also took more than a month to finally make the cache of files private.
Researcher Niall Merrigan discovered the cache by scanning certificate transparency logs created when someone creates a new security certificate.
Yet True Move H and parent True Corp are continuing to characterize the action as a data breach. A True Corp executive told that the company is considering taking legal action for hacking the data from the system, stating that he used “special tools to access data which he has no right to get into.”
But a cloud expert noted that because the default setting for the AWS S3 service is private, True had to have intentionally set the data to public.
Questions & Answers
Q.What kind of customer data was exposed in the leak?
What kind of customer data was exposed in the leak?
The personal data leak involved customers' identity documents. These documents belonged to users of True subsidiary iTrueMart, with up to 45,736 individuals potentially affected by the exposure.
Q.How long did it take True Move H to secure the exposed customer data?
How long did it take True Move H to secure the exposed customer data?
True Move H took over a month to make the cache of customer files private. The data had been stored in a publicly-accessible Amazon S3 data bucket for that period before being secured.
Q.What action is True Corp considering against the security researcher?
What action is True Corp considering against the security researcher?
True Corp is considering legal action against the security researcher, Niall Merrigan, for hacking their system. An executive stated the researcher used 'special tools to access data which he has no right to get into'.
Q.What is the NBTC doing in response to the data leak?
What is the NBTC doing in response to the data leak?
The NBTC has instructed True Move H to assess the leak's impact and offer compensation. The regulator also plans a formal investigation, considering punishments, and will issue a letter to all mobile operators regarding future breach prevention.
Reader pulse
What's the biggest takeaway for True Move H?
20,714 votes so far