Thai consumers increasingly vulnerable to scams in AI era
Thai consumers remain highly vulnerable to financial scams, hacking and debt traps — and the rapid emergence of artificial intelligence (AI) could worsen the risks.
Authorities have tried to reassure the public that their crackdowns on financial crime had reduced the number of scam cases.
However, frequent news reports of victims being duped into transferring money by illegal call centres continue to shake public confidence.
“Catching them is not an easy task, as scammers operate like guerrilla warfare — moving from one place to another and they do not need much resources,” explains Prinya Hom-Anek, executive chairman at ACIS Professional Center and Cybertron Company Limited.
These scammers operate in several provinces, including Greater Bangkok and border provinces such as Sa Kaeo in the East, he says.
Many have relocated to Laos after crackdowns on their former bases in Myanmar and Cambodia by international coalitions, Prinya adds.
Systemic weaknesses stand exposed
News reports have revealed that personal data stored by government agencies and financial regulators had been repeatedly breached.
In early August, Thai authorities launched a cross-agency investigation into unauthorised access to government databases after personal information linked to members of the public, the prime minister, Cabinet ministers and senior officials appeared online.
The latest incident involved vehicle-registration information held by the Department of Land Transport, renewing concerns over whether government agencies have adequate safeguards for personal data.
This followed an earlier breach in which information on about 200,000 investors was exposed from more than 5 million shareholder accounts maintained by Thailand Securities Depository Co Ltd.
Data leak of 67 million Thai citizens
Personal data leaks are not new, but a recent revelation that data belonging to more than 67 million citizens may have been accessed by malicious actors has raised serious concerns about cybersecurity in Thailand’s public sector, especially whether the weakness lies in systems or in human behaviour.
Thanarat Kuawattanaphan, CEO of DomeCloud and an expert in software and blockchain technology, said that the monitoring of personal data trading groups on platforms such as Discord and Telegram had revealed a massive dataset linked to Thai citizens’ healthcare-rights databases, totalling over 67.1 million records.
The data includes full names, national ID numbers, home addresses, healthcare entitlements and, in some cases, information about parents. This significantly increases the risk of the data being used in more sophisticated criminal activities.
Compromised computers of officials
A key observation from Thanarat is that most of the leaked data did not come from direct server hacking. Instead, it resulted from credential theft on government officials’ computers infected with malware.
In many cases, pirated software, unsafe downloads or risky websites allowed stored passwords to be harvested and used to access official systems.
If this assumption is correct, the core problem is not just central system intrusion, but user-level vulnerability that serves as a gateway for attackers.
So far, however, no major perpetrator has been brought to justice.
Side-effects of the anti-scam campaign
As authorities and police intensify efforts to crack down on financial scams, some innocent people have found their bank accounts unexpectedly suspended.
The Bank of Thailand (BOT) recently clarified its guidelines on account suspension and unfreezing, emphasising both a crackdown on mule accounts and rapid relief for honest citizens.
BOT assistant governor of the payment systems policy and financial consumer protection group Sakkapop Panyanukul said the central bank understood the impact on members of the public whose accounts were frozen under mule-account measures, particularly those with no intention of wrongdoing who must still undergo verification to regain normal access.
Historically, the BOT has pursued two parallel tracks:
1. promptly blocking high-risk accounts to prevent stolen funds from being moved further; and,
2. speeding up verification and unfreezing so innocent users can resume using financial services as quickly as possible.
Different “shades” of mule accounts
Requests to unfreeze accounts are not automatically applied across all accounts, as channels and authorities differ depending on the risk level and reason for suspension:
● Dark Black and Dark Grey Mule — High-risk accounts where victims have filed police reports and officers have confirmed illicit activity. Account holders must request an unfreeze via the Anti-Money Laundering Office (AMLO) and the Cyber Crime Investigation Bureau (CCIB), respectively.
● Light Grey Mule — These are accounts linked to scam incidents where the victim has not yet filed an official complaint. Owners must request unfreezing account by account with the bank directly connected to the damage. Once all related accounts are cleared, the owner’s name can be removed from the watchlist.
● Dark Brown Mule — These are accounts flagged by banks for unusual activity, with enough evidence for banks to notify other banks and the police even without a reported victim. Account owners must request an unfreeze from the bank that detected the suspicious activity.
The BOT has stressed that account suspension for investigation does not mean the account holder has been found guilty.
It is a preventive step to stop potentially fraudulent funds being moved during the probe. Innocent parties can present facts and evidence for review.
Where accounts cannot yet be unfrozen, additional fact-finding may still be underway, or existing data may be insufficient to verify the origin and sources of funds.
Enhanced due diligence is required to ensure accounts tied to wrongdoing do not re-enter the financial system, while avoiding unnecessary delay for innocent users.
The mule-account suppression policy is a joint effort of the BOT, financial institutions, AMLO, CCIB and other agencies to block criminal financial channels.
During the joint operation period, losses from scam-related voluntary transfers fell from a peak of about 8.59 billion baht in Q2 of 2024 to about 1.81 billion baht in Q2 of 2026.
Still, the BOT acknowledges that effective measures must be balanced with minimizing harm to innocent citizens.
Banks have been instructed to clearly inform affected customers about the reason for suspension, the relevant agency or bank to contact, required documents and appeal steps, to prevent confusion and speed up reviews.
‘Buy Now, Pay Later’ trap
Household debt in Thailand remains close to 90 per cent of GDP, prompting regulators to scrutinise “buy now, pay later” and other non-bank lending practices.
BOT Governor Vitai Ratanakorn has said that new measures will rein in non-bank lenders, including setting limits on loan sizes and stronger prudential lending guidelines. He aims to have the new rules in place this year.
Critics complain about loopholes in the law and weak enforcement.
“Some scammers have disguised themselves as online lenders via applications, while some micro‑lenders licensed by regulators should not be allowed to launch lending via apps — regulators have to look at this issue,” says Adisak Saiprasert, head of the policy support unit at the Thailand Consumers Council.
He points out that the country’s legal system has not kept pace with platform- and app-based lending, leaving consumers at a disadvantage.
AI Era: New technology, new threats
OpenAI, Anthropic and Meta have recently disclosed that their AI tools performed actions during test runs that were not anticipated — including attempts to hack other companies’ databases without permission.
“More advanced AI would make cybersecurity even worse. Therefore, to safeguard ourselves, we have to embrace critical thinking and rationality,” Prinya suggested, referring to how people are often lured by false promises of financial rewards offered by scammers.