itap.nacc.go.th Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
itap.nacc.go.th has been listed by the killsec ransomware group, with internal files reportedly exfiltrated during the attack. The incident came to light on 30 September 2024, but the actual date of the intrusion has not been established. Individuals connected to the organisation should verify whether their information was exposed and review any guidance issued by itap.nacc.go.th.
People whose information may sit inside systems linked to Thailand’s Integrity and Transparency Assessment of Public Service now face a practical question: whether internal files taken in a claimed ransomware attack could expose them to fraud, targeted scams or unwanted contact. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has interacted with the programme or related government services.
On 30 September 2024 the domain itap.nacc.go.th appeared on a leak site operated by the ransomware group killsec. The group claims to have exfiltrated internal files. The number of people affected is unknown, and the precise contents of those files have not been independently confirmed.
Breaking down the breach
According to the available record, the Integrity and Transparency Assessment of Public Service site was listed by killsec on 30 September 2024. The only description supplied is that internal files were allegedly exfiltrated in a ransomware attack. No further technical detail—such as the initial access method, the exact date of intrusion, the volume of data, or any ransom demand—has been disclosed in the public summary. The number of individuals whose records may be involved is listed as unknown. Because the listing originates from the threat actor’s own site, it constitutes a claim rather than an independently verified confirmation of compromise.
At present there is no public statement from the National Anti-Corruption Commission or the ITAP programme confirming or denying the incident. Until such verification appears, the scale and full impact remain unconfirmed.
The group behind it: killsec
Killsec is a ransomware operation that has been observed publishing victim names and sample data on dedicated leak sites when negotiations stall. Like many groups in this category, it typically claims to have stolen files before encrypting systems, then uses the threat of public release as leverage. Public reporting over recent years has associated killsec with opportunistic attacks against organisations of varying size, often focusing on data that can be monetised or used for further pressure. The group’s listings are self-reported claims; they do not automatically prove that every file set is authentic or complete. In this case the only assertion on record is that internal files from itap.nacc.go.th were taken.
Who is itap.nacc.go.th?
The Integrity and Transparency Assessment of Public Service, or ITAP, is an initiative run under Thailand’s National Anti-Corruption Commission. Its purpose is to evaluate the ethical standards and transparency practices of government agencies across the country. Systems supporting such assessments commonly hold organisational questionnaires, scoring data, contact details for agency officials, and internal correspondence related to compliance reviews. Because the programme sits inside the anti-corruption framework, any unauthorised access carries implications for both institutional trust and the individuals whose professional details may appear in those records.
A breach affecting an assessment platform of this kind is consequential precisely because the data often describe how public bodies handle integrity questions. Even if the files are administrative rather than highly personal, their exposure can still create secondary risks for staff and for the agencies being evaluated.
The information in question
The public record states only that “internal files” were exfiltrated. No inventory of specific data types—such as names, national identification numbers, email addresses, financial records or assessment scores—has been released. Organisations that run transparency and integrity programmes typically store contact information for civil servants, internal reports, evaluation criteria and correspondence. Whether any of those categories were present in the claimed file set remains unconfirmed. Until a fuller disclosure or official confirmation appears, the exact contents should be treated as unknown.
Why it matters
For individuals, the practical risks centre on the possible misuse of professional or contact details that may have been stored in the system. Even limited internal files can supply enough context for convincing phishing messages or social-engineering attempts that reference genuine agency work. For the organisation, the incident raises questions about the confidentiality of integrity assessments and the potential chilling effect on open reporting by government bodies. Because the number of people affected is unknown, the full scope of personal exposure cannot yet be measured. The absence of confirmed data types also means that affected parties must prepare for a range of possibilities rather than a single clear threat.
If your data was in this claimed breach
If you have had any professional or administrative contact with the ITAP programme or the National Anti-Corruption Commission, treat the possibility of exposure seriously while recognising that confirmation is still pending. Practical first steps include:
- Monitor official email and messaging accounts for unexpected requests that reference integrity assessments or government transparency work.
- Enable multi-factor authentication on any accounts that share credentials or recovery details with government-related services.
- Review recent account activity for unfamiliar logins or password-reset attempts.
- Be cautious of unsolicited calls or messages that claim to come from anti-corruption or assessment bodies and ask for further personal information.
- Consider running a free exposure scan of your email address against known breach data sets to see whether your details have already appeared elsewhere.
Public detail on this incident remains limited. Continue to watch for any official statement from the National Anti-Corruption Commission that may clarify what was taken and who is affected. Until then, measured vigilance is the most useful response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
JSSR Options Co., Ltd. (JSSR) Listed by killsec Ransomware Groupmoi.gov.ly Listed by killsec Ransomware Grouptransfoodbeverage.com Listed by killsec Ransomware Groupnfe.fazenda.gov.br Listed by killsec Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the itap.nacc.go.th Listed by killsec Ransomware Group →
Publicly posted by killsec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.