Thailand's Largest Mobile Network Exposed 8 Billion Internet Users' DNS Records

AIS is Thailand's largest mobile network. Also known as 'Advanced Info Service Public Company Limited', it is the country's largest GSM mobile phone operator with 39.87 million customers as of the third-quarter of 2016.

Founded in April 1986, AIS began as a computer-rental business, before venturing to providing mobile phone services.

The company that is controlled by the Intouch Holdings (Shin Corporation), headed by Temasek Holdings, a Singapore government-owned agency, was found to have leaked billions of real-time internet records of millions of Thai internet users.

Discovered by security researcher Justin Paine, in a blog post, he said that he found an online database that contained DNS queries and Netflow data, that is accessible without a password.

Paine alerted AIS about his findings on May 13. But because he didn't receive a respond after about a week, Paine reported his findings to ThaiCERT, which is Thailand’s national computer emergency response team.

It was then ThaiCERT that contacted AIS.

AIS Thailand leaking DNS records.
AIS Thailand leaking DNS records. (Credit: Justin Paine)

Quickly after ThaiCERT's alert, AIS made the database inaccessible.

While the owner of the database is unknown, at least at this time, Paine said that the records inside the database could only come from those or companies that monitor internet traffic as it flows through the network.

Paine suggested that the owner could be the internet provider or one of its subsidiaries, a large enterprise customer on AIS’ network, or others who have involvement or is a partner of AIS.

The scary thing about this leak is that, according to Paine, anyone who finds the database, could “quickly paint a picture” about what an internet user (or their household) does in real-time.

This kind of database holds DNS queries, and it's common for providers to collect this kind of data. This happens because every time users visit a website, browsers have to convert the readable web address to an IP address. And this data is known to internet service providers.

While this kind of database does not store private messages, emails or passwords, they can still provide enough information to identify users.

For example, anyone who has access to this kind of database, could know what kind of devices users use, which antivirus they ran, which browsers they used, and which social media apps and websites are frequented visited.

[block:block=87]

Because DNS query data can also be used to gain insights into a person’s internet activity. the leak could be a huge risk to high-risk individuals, like politicians, high-profiled businessmen, journalists and activists, whose internet records could be used to identify their sources, or disclose some secrets that shouldn't be made public.

Advertisers and scammers could also find DNS data valuable.

Making things worse for Thailand is that, the country's internet surveillance laws grant authorities sweeping access to internet user data. Thailand also has some of the strictest censorship laws in Asia, forbidding any kind of criticism against the Thai royal family, national security, and certain political issues. I

In all, around 8.3 billion records worth 4.7 TB of data were exposed to the public internet.

At the moment of Paine's finding, the database was adding about 200 million new rows every 24 hours, about 1 million new unique IPs were recorded every 24 hours, and the NetFlow data was being logged at rate of roughly 3,200 events per second.