Cybercrimes in Thailand: Responsibility and Protection
Planet

Cybercrimes in Thailand: Penalties for Offenders and How to Protect Yourself

Digital technology has transformed banking, tourism, commerce, and everyday communication in Thailand. At the same time, phishing, account takeovers, ransomware, online investment fraud, identity theft, malware, and the misuse of payment accounts have become significant risks for individuals and businesses.

Thailand addresses these offences through several legal instruments rather than one general “cybercrime law.” The principal criminal statute is the Computer Crime Act B.E. 2550 (2007), as amended by the Computer Crime Act No. 2 B.E. 2560 (2017). Other cases may also involve the Thai Criminal Code, the Personal Data Protection Act, the Cybersecurity Act, anti-money laundering rules, and legislation targeting technology-related financial crime.

Anyone accused of a cyber offence should avoid assuming that technical evidence is automatically conclusive. IP addresses, device identifiers, account records, server logs, and cryptocurrency transactions must still be linked to a particular person and interpreted in context.

What Constitutes a Cybercrime under Thai Law

The Computer Crime Act does not define every unlawful act involving a phone or computer as a separate cybercrime. Instead, it creates specific offences involving computer systems, computer data, protected access measures, harmful programs, and certain types of online content.


The Act covers conduct such as:
– unlawfully accessing a protected computer system;
– unlawfully accessing protected computer data;
– intercepting non-public data during transmission;
– damaging, deleting, altering, or adding to another person’s computer data;
– disrupting the normal operation of another person’s computer system;
– distributing programs specifically designed for computer offences;
– fraudulently introducing false or distorted data likely to harm the public;
– knowingly distributing certain unlawful computer data;
– creating or publishing manipulated images in circumstances covered by the Act.

The legal classification depends on the exact conduct. For example, online fraud may involve both Section 14 of the Computer Crime Act and fraud provisions in the Criminal Code. Theft of personal information may also raise issues under the Personal Data Protection Act.


The 2017 amendment expressly distinguishes false-data offences under Section 14 from ordinary criminal defamation. Therefore, not every inaccurate, insulting, or disputed online statement automatically constitutes a Computer Crime Act offence.


Attacks on systems connected with national security, public safety, economic security, or public infrastructure may result in substantially higher penalties. Thailand separately applies the Cybersecurity Act B.E. 2562 (2019) to the prevention, management, and mitigation of cyber threats affecting government bodies and critical information infrastructure.

Legislative Framework and Penalties for Cybercrimes

The applicable punishment depends on the section charged, the system affected, the damage caused, and whether additional offences under the Criminal Code or other legislation are alleged.


Under the Computer Crime Act:
– unlawful access to a protected computer system may result in imprisonment for up to six months, a fine of up to 10,000 baht, or both;
– unlawful access to protected computer data may result in imprisonment for up to two years, a fine of up to 40,000 baht, or both;
– unlawful interception of private computer data may result in imprisonment for up to three years, a fine of up to 60,000 baht, or both;
– unlawfully damaging, destroying, altering, or adding to another person’s computer data may result in imprisonment for up to five years, a fine of up to 100,000 baht, or both;
– disrupting another person’s computer system may carry the same maximum penalty of five years and 100,000 baht.

More serious penalties apply when protected systems relate to national security, public safety, economic security, or public infrastructure. Certain attacks on such systems may lead to imprisonment of between three and 15 years and fines of between 60,000 and 300,000 baht. Where the conduct causes death without an intention to kill, the Act provides for imprisonment of between five and 20 years and a fine of between 100,000 and 400,000 baht.

Section 14 generally provides a maximum penalty of five years’ imprisonment, a fine of up to 100,000 baht, or both for specified false-data, public-security, terrorism-related, or publicly accessible obscene-data offences. Where fraudulent false data affects a particular person rather than the public, a lower maximum of three years and 60,000 baht may apply.

Online financial scams are also governed by the Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes B.E. 2566 (2023). Thailand amended this framework in 2025 to strengthen cooperation and responsibility among financial institutions, payment providers, telecommunications companies, social platforms, and digital-asset businesses. The framework supports faster information sharing, transaction suspension, and action against mule accounts.

The Ministry of Digital Economy and Society oversees the Computer Crime Act. Criminal investigations may involve local police, specialist investigators, or the Royal Thai Police’s Cyber Crime Investigation Bureau, commonly known as the CCIB.

Investigation of Cybercrimes and International Cooperation

Cybercrime investigations may involve phones, computers, cloud accounts, email records, server logs, payment data, social-media accounts, CCTV footage, and digital-asset transactions. Investigators must determine not only what occurred but also who controlled the relevant device or account at the material time.

Under Section 18 of the Computer Crime Act, authorised officials may request statements, documents, traffic data, subscriber information, and the preservation of relevant records. They may also seek access to systems, copies of data, decryption assistance, or the seizure of computer equipment.

Several intrusive measures require prior authorisation from a competent court under Section 19. An application must explain the suspected offence, the reasons for using the requested power, and the relevant system or equipment. Computer systems generally cannot remain seized for more than 30 days without a court-approved extension. The combined extensions may not exceed an additional 60 days.

Digital evidence does not automatically become invalid because of a minor technical error. However, the defence may examine whether the authorities obtained it lawfully, preserved it correctly, documented its source, and demonstrated that it remained reliable.

Cross-border investigations may involve police-to-police cooperation, mutual legal assistance, requests to overseas service providers, or extradition proceedings. Thailand’s INTERPOL National Central Bureau connects Thai law enforcement with foreign NCBs and the INTERPOL General Secretariat through the I-24/7 network.

Claims that Thai investigators can automatically obtain data from any foreign exchange or platform are inaccurate. Access depends on Thai law, the location of the data, the provider’s rules, and the applicable international cooperation process.

Liability of Individuals and Legal Entities

Individuals may face liability when the evidence proves the required conduct and mental element. The mere fact that a phone number, IP address, bank account, or company device appears in an investigation does not necessarily establish who committed the offence.

The Computer Crime Act also imposes specific obligations on service providers. Under Section 15, a provider that cooperates with, consents to, or knowingly permits a Section 14 offence within a system under its control may face the same punishment as the principal offender. However, a provider may avoid that liability by following the official notice, suspension, and removal procedures.

This provision should not be interpreted as a general rule that every company becomes criminally liable whenever an employee commits an offence or whenever a cybersecurity incident occurs. Corporate and executive liability depends on the relevant statute, the person’s role, knowledge, participation, and the evidence.

Businesses may nevertheless face separate regulatory consequences when a data breach reveals failures under the Personal Data Protection Act, sector-specific cybersecurity requirements, financial regulations, or contractual obligations. A personal-data breach and a criminal computer offence are related issues in some cases, but they are not legally identical.

Foreign nationality does not provide immunity. Section 17 of the Computer Crime Act also permits prosecution in Thailand for certain offences committed abroad. This includes specified cases involving a Thai offender or a foreign offender where the Thai government or a Thai person is the injured party and the required complaint or request has been made.

Defense in Cybercrime Cases

A cybercrime defence usually begins with identifying the exact statutory provision and separating technical facts from assumptions.


Important questions may include:

  • Who owned and controlled the device or account?
  • Could another person access the credentials?
  • Does the evidence show deliberate access or only an automated connection?
  • Were timestamps, IP addresses, and time zones interpreted correctly?
  • Was the data altered, incomplete, or taken out of context?
  • Did the authorities obtain the necessary court approval?
  • Does the alleged conduct satisfy every element of the charged offence?
  • Is the prosecution relying on the Computer Crime Act, the Criminal Code, or several laws at once?

Independent forensic analysis may be necessary where the case involves shared devices, compromised accounts, remote-access software, malware, deleted data, cloud storage, or complex cryptocurrency transactions.
Intent is also important. However, lack of intent cannot be assumed merely because a person describes an action as accidental or work-related. The defence must compare the explanation with system records, communications, permissions, professional duties, and the wording of the relevant offence.
A person under investigation should preserve potentially relevant data and avoid deleting messages, resetting devices, transferring digital assets, or contacting witnesses in a way that could be interpreted as interference. Before providing a detailed statement, the person should understand the allegation and obtain advice on the possible consequences.

Cybersecurity and Prevention

Individuals can reduce their exposure to cybercrime by using unique passwords, enabling multi-factor authentication, updating software, verifying payment requests, and avoiding unknown links or applications. Encryption and two-factor authentication are among the protective measures promoted by Thailand’s National Cyber Security Agency.

Businesses should apply a more structured approach:

  • restrict access according to job responsibilities;
  • maintain secure and tested backups;
  • record administrator activity;
  • update operating systems and applications;
  • protect remote-access services;
  • train employees to recognise phishing and impersonation;
  • establish procedures for data breaches and financial fraud;
  • preserve logs and evidence after an incident;
  • identify who must contact banks, police, regulators, and affected customers.

When an online financial scam occurs, the victim should contact the relevant bank or payment provider immediately. Thailand’s current anti-technology-crime framework is designed to enable faster reporting, information exchange, and temporary suspension of suspicious transactions, although recovery of funds is not guaranteed.
Companies should not attempt to “clean up” an incident by deleting accounts, wiping systems, or altering logs before forensic preservation. Such actions may destroy evidence needed to identify the attacker or defend the organisation against later allegations.

How Our Legal Team Can Help

Cybercrime is not just a legal violation but a field where technology and jurisprudence are closely intertwined. Our team specializes in cases related to the Computer Crime Act and offers comprehensive client support at all stages — from investigation to trial.
We conduct an initial legal assessment of the situation, analyze digital evidence, and develop a defense strategy considering the specifics of Thai law. If necessary, we involve experts in computer forensics and international law, ensuring a comprehensive approach.
We also protect the interests of companies affected by cyberattacks, helping restore data, interact with the police, and limit reputational risks. For foreign clients, we provide full support in English, Russian, and Thai.
Our practice shows that success in such cases depends on the speed of response and the right strategy. Timely consultation with a lawyer helps prevent asset seizure, account blocking, and other measures that can seriously harm business.

Conclusion

Thailand’s cybercrime framework combines the Computer Crime Act with the Criminal Code, cybersecurity regulation, personal-data law, and newer measures targeting technology-related financial scams.

The Computer Crime Act gives investigators significant powers, but several intrusive actions require judicial approval. Prosecutors must still prove the elements of the alleged offence and connect the evidence to the accused person.

For individuals and businesses, prevention depends on technical security, clear internal procedures, rapid incident reporting, and proper preservation of evidence. When an investigation begins, early legal and forensic analysis can help clarify the allegation, protect procedural rights, and prevent avoidable damage to the case.

Marcin Ajs
Associate Partner
Advocate, expert in international and white-collar criminal law. Partner at Dziekański Chowaniec Ajs and member of the European Criminal Bar Association. Since 2014, he has represented clients in cases involving the European Arrest Warrant, INTERPOL Red Notices, and extradition. He advises companies and individuals on criminal liability, corruption, VAT fraud, and financial crimes. He also develops compliance programs to prevent legal risks.

    Planet
    Planet