Bangkok Post – TSD investor data breach cue for SEC action

TSD investor data breach cue for SEC action

The Securities and Exchange Commission (SEC) is monitoring Thailand Securities Depository Co (TSD) after the central securities depository detected unauthorised access to personal data stored on its TSD Investor Portal.

Anek Yooyuen, deputy secretary-general and spokesman of the SEC, said the regulator received a preliminary incident report from TSD on July 26 after the company identified unauthorised access to its investor portal system.

“The SEC immediately coordinated with TSD to establish the facts, determine the root cause of the incident and ensure appropriate measures are implemented to prevent any further impact,” Mr Anek said.

The SEC said TSD blocked access from suspicious sources and user accounts, disabled affected system connections and stepped up cybersecurity monitoring as part of its containment measures.

TSD confirmed separately that the incident resulted in the exposure of some users’ personal information. The company said it immediately isolated the affected system, stopped the data leakage and strengthened cybersecurity surveillance to prevent further unauthorised access.

TSD stressed that the incident did not affect securities trading, financial information or investor assets it holds in custody. Trading and settlement operations continue to function normally.

The company said it complied with relevant legal requirements, including notifying regulatory authorities and informing individuals whose personal data may have been affected.

Cybersecurity push

The incident highlighted the growing importance of stronger cyberdefence across Thailand’s financial market infrastructure as more investor services move online.

TSD said it enhanced its cybersecurity monitoring framework and was conducting continuous risk assessments to detect abnormal activity. The company is also working with the SEC to investigate the underlying cause of the unauthorised access.

The SEC said it would continue coordinating with TSD to ensure corrective measures were implemented and any remaining vulnerabilities were addressed to minimise the risk of other similar incidents.

The regulator warned that personal information exposed in a data breach could potentially be exploited in phishing and social engineering scams. Investors were urged to exercise caution when receiving emails, SMS messages or phone calls requesting personal, financial or account information.

Investors should not click on suspicious links or disclose passwords and other sensitive credentials to anyone whose identity cannot be independently verified, the SEC said.

TSD recommended users of its investor portal change their passwords regularly and review the security of other online accounts that use similar login credentials.

As an additional precaution, the company sent notification emails to users who may have been directly affected by the incident, advising them to remain vigilant for suspicious communications.

Confidence maintained

The SEC said protecting investor information remains a regulatory priority and it would continue monitoring TSD’s response until the investigation was completed and appropriate safeguards were fully implemented.

Mr Anek said the cooperation between the SEC and TSD was focused not only on determining how the unauthorised access occurred, but also on strengthening preventive measures to reduce the likelihood of similar incidents in the future.

Investors seeking further information should follow announcements from TSD or contact its contact centre.

The SEC urged people to report suspicious activity or potential fraud through its complaint and whistleblower channels.

The coordinated response is intended to reinforce confidence in Thailand’s capital market infrastructure while strengthening the protection of investor data against evolving cyberthreats, he added.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *