Tuesday, 22 September 2026 The Plausible Post Independent news from around the world, around the clock.

Leaked 'Krabi Ledger' Shows Thai Telecom Sold 12 Billion Location Pings to Shadow Buyers

A leaked 44-terabyte cache published this weekend alleges Thailand’s largest mobile operator sold millions of customers’ location and device telemetry to opaque overseas firms. The files have triggered raids, arrests and an emergency regulator inquiry amid questions whether elderly care devices and mobility scooters were among the trackers sold.

By Carmen Schütte ·

Journalists review printed pages from the leaked dataset outside the telecom's office in central Bangkok on Monday morning.
Journalists review printed pages from the leaked dataset outside the telecom's office in central Bangkok on Monday morning.

A trove of internal logs dubbed the “Krabi Ledger” has exposed what investigators say was an organised, multi‑year programme by the major Thai operator SiamTel to monetise raw location and health‑device telemetry from subscribers and third‑party care devices. The files — 44 terabytes of raw logs spanning January 2018 to June 2026 — include 12 billion individual location pings tied to 4.6 million unique device IDs and, according to analysts who reviewed the dump, records labelled as “eldercare_telemetry” and “mobility_vehicle_feed.”

The ledger, distributed on Saturday to three journalists in Bangkok and an international transparency group, lists more than THB 2.8 billion (about $78 million) in payments between SiamTel and a web of shell buyers registered in Singapore, Belize and the UAE. One buyer is named in the files as Pacific Frontier Analytics; another as Argos Data Labs — firms that, investigators say, repackaged raw location streams into minute‑by‑minute movement models sold to hedge funds, political consultants and overseas intelligence contractors.

Police and data regulators moved within 48 hours. On Sunday morning (20 September) officers from the Technology Crime Suppression Division, accompanied by National Broadcasting and Telecommunications Commission (NBTC) inspectors, executed warrantees at two office blocks in Sathorn and Bang Na and seized servers and laptops, the attorney general’s office confirmed. Two men described in public filings as mid‑level sales executives were detained for questioning on suspicion of breaching the Personal Data Protection Act. "We will not tolerate the commercial sale of people’s intimate location data," NBTC acting chair Supatra Vong said at a press briefing. "We have opened an urgent administrative probe and referred criminal leads to prosecutors."

Technology Crime Suppression Division officers remove servers and equipment from a Sathorn office during Sunday’s raids.
Technology Crime Suppression Division officers remove servers and equipment from a Sathorn office during Sunday’s raids.

A former engineer who asked to speak on the record described how the pipeline worked. "I was hired to normalise telemetry into feeds — strip names but keep persistent device hashes and enrich them with purchase, banking, and transit tags," said Uzodimma T. Muinat, who said he worked on the programme at a subcontractor between 2020 and 2023. "Once you can predict a person’s route with 95% confidence, you can sell that slice to anyone who pays — advertisers, traders, outfits running influence operations. It was treated like electricity: metered and billed."

Among the most explosive entries in the ledger are event logs from medical and mobility aid devices: fall‑detection bands, at‑home oxygen concentrators and the GPS modules on power-assisted scooters marketed to seniors. Families of two elderly victims whose devices appear in the logs say authorities have reopened their cases. "My husband’s scooter cut out on 23 July 2024 and the ambulance could not find him for 17 minutes," said Rosa Morelli, whose husband, a 95‑year‑old Italian expatriate, died that day. "Now we see his last movements were part of a data sale. They treated him like a commodity."

Markets reacted fast. SiamTel’s shares plunged 37% on Monday morning, wiping about THB 150 billion (roughly $4.2 billion) off the company’s market capitalisation as major institutional investors suspended trading of the stock. Several Thai banks told reporters they were reviewing credit lines tied to companies named in the ledger. The country’s data protection office warned companies that profiting from unauthorised transfers could attract fines that reach up to THB 5 million and criminal penalties for executives, while civil suits from victims are already being prepared.

The leak raises wider regional alarms about a thriving subterranean market for raw mobility and health telemetry. "This is a structural problem for any country where mobile operators control both the network and an ecosystem of care and IoT devices," said Cem Akbulut, a Bangkok‑based privacy lawyer. "Regulators must demand source audits, compel notification to affected users and impose criminal liability for deliberate concealment."

For now, prosecutors say the investigation will prioritise requests to freeze assets and trace the offshore recipients. Political parties have called for emergency parliamentary hearings this week. SiamTel issued a short statement acknowledging it had "engaged with third‑party analytics companies" but said it would "co‑operate fully" and had suspended the individuals named in the ledger. A larger reckoning over how personal movement traces are traded as a routine commodity — and who bears the legal and moral cost — looks set to unfold in Bangkok and in data courts abroad.

More news