On September 30, 2024, the Thai government agency initiative known as ITAP.nacc.go.th appeared on the leak site operated by the ransomware group Killsec. The listing states that internal files were exfiltrated during a ransomware attack on the Integrity and Transparency Assessment of Public Service platform run by Thailand’s National Anti-Corruption Commission.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch itap.nacc.go.th
Get alerted the next time itap.nacc.go.th files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about itap.nacc.go.th’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Leak
The primary disclosure on the Killsec onion site indicates that data was taken from the ITAP system, which evaluates ethical standards and transparency across Thai government agencies. The listing does not quantify how many records were allegedly stolen, nor does it specify the exact types of internal files beyond describing them as exfiltrated documents. No ransom demand figure is published on the page, and the notification does not list specific categories such as names, national ID numbers, or email addresses. What is certain is that the victim is a public-sector transparency program under the NACC, making any leaked material potentially sensitive to both government operations and the individuals whose information appears inside assessment records.
Why This Matters for You and Your Family
When a government transparency platform is breached, the exposure can reach far beyond bureaucrats. Citizens, contractors, and public employees who interacted with the ITAP assessment process may have had personal details stored in the compromised files. If your name, contact information, or government-related records were part of any ethics or transparency review, those details may now be in the hands of criminals. For ordinary families this means heightened risk of targeted phishing, impersonation, or demands for payment to prevent further release of information. Even when exact record counts remain unknown, the public nature of the victim organization raises the likelihood that everyday Thai residents and their families are indirectly affected.
Doxxing and Identity-Chain Risks
Internal government files frequently contain more than isolated data points; they link names to addresses, phone numbers, government IDs, and sometimes family member details. Once published on a ransomware leak site, this information can be scraped and combined with other breaches to build complete identity profiles. Attackers chain these records with credential leaks from unrelated services, turning one government breach into a gateway for account takeovers across email, banking, and social media. Children’s gaming accounts are especially vulnerable because parents often reuse passwords or email addresses tied to official records. The result is a doxxing cascade that can expose your household’s full digital footprint within weeks of the initial leak.