Advance Info Service, Thailand’s largest mobile operator, said that a database leak which released 8.3 billion internet records of millions of customers did not contain any sensitive information and that it had shut down the database.
US tech website TechCrunch was the first to report that AIS’s database was accessible to anyone without a password and the leaked information could be used to track and construct pictures of what households were doing on their internet connection.
AIS has stated that the database were part of a test to improve customer experience.
No customer was affected financially and in any other way, as the logs contained only a small amount of non-personal and non-critical information, the company emphasised.
“All of the data was related to internet usage patterns and did not contain personal information that could be used to identify any customer,” AIS Chief of Public Relations Saichon Sapmakudom said.
“We are very committed to protecting our customers’ privacy and have continued to diligently comply with the highest international privacy standards.”
Sapmakudom acknowledged that their procedures fell short, and later apologized for the security lapse.
However, claims of the leaked information being non-personal and non-critical may be untrue.
What can you do with this data?
One researcher said that the information leaked included DNS queries from internet users.
“Using this data it is quite simple to paint a picture of what a person does on the Internet” said security researcher Justin Paine in an article on TechCrunch. “I made multiple attempts to contact AIS to get the database secured without success.”
“At that point I contacted Zack Whittaker – a journalist from TechCrunch – for assistance.”
“Although DNS queries don’t carry private messages, emails, or sensitive data like passwords, they can identify which websites you access and which apps you use,” Whittaker wrote in the TechCrunch article.
This could have serious implications for high-risk individuals such as “journalists and activists, whose internet records could be used to identify their sources.”
When was this data exposed?
The database, based on data available on BinaryEdge, was first observed as exposed and publicly accessible as early as May 1, 2020.
Paine discovered the exposed data roughly a week later on May 7. After which he made “multiple attempts” to contact the owner of the database, but to no avail.
They managed to get the database secured on May 22 after reaching out to the Thailand National CERT team (ThaiCERT) who successfully made contact with AIS about the open database.
Both TechCrunch and Paine said they never heard back from AIS until after their article was published.


