Skip to content

Read the DRAPAC23 Statement of Solidarity

  • Digital Rights
  • Open Technology
  • Video For Change

Phishing attacks targeting Myanmar and Thai activists

  • 15 June 2023
  • 11:08 am

This post is also available in: Thai


This post was produced with input from the Spring Revolution Security Telegram Channel.

Recently, several human rights defenders and digital rights activists from Thailand and Myanmar have been targeted by phishing attacks through Telegram. Some of those targeted by phishing attempts have had their accounts hacked and their digital security compromised.

The messaging platform is commonly used by activists because of its security features, but it is not completely safe. For instance, there have been issues regarding doxing on Telegram, especially targeting pro-democracy activists in the wake of the Myanmar coup. Additionally, users on Telegram and other platforms are also prone to various types of phishing attacks employed by cybercriminals to gain unauthorised access to an organisation’s networks and computers, introduce malware, and trick victims into sharing sensitive information.  

It is important to practice heightened digital security procedures to keep yourself safe. Do not click on suspicious links (note the telegram.im and telegram.org domains). Clicking on suspicious links will put you at risk of losing access to the Telegram account associated with the compromised phone number.

Messages received by activists in Thailand and Myanmar

 

Here are some recommendations to keep yourself safe:

  • If you receive a message such as the one above, your phone number may already have been compromised. Change your number immediately in the settings.
  • Configure your privacy settings to avoid revealing your phone number. 
  • Two-factor authentication is a must. 
  • Regularly check your active sessions and remove unused or unfamiliar devices. 

Moreover, we recommend linking Telegram with a throwaway phone number that you can discard if compromised. 

If you are logged in to multiple devices (for example, an active session on your phone and on your laptop), never request log-in codes through SMS. 

Learn more about enhancing your digital safety through these guides:

  • Digital Hygiene 101: How to practise digital safety and security 
  • #HumanOnTheLine: Digital rights campaign in Thailand 
  • #DigitalSafetyFirstMM 
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

Subscribe to the EngageMedia mailing list

Two emails a month of all our best posts. View past newsletters.

Subscribe now!

EngageMedia is a non-profit media, technology, and culture organisation. EngageMedia uses the power of video, the Internet, and open technologies to create social and environmental change.

Mastodon X-twitter
  • Home
  • Video
  • Blog
  • Podcast
  • About
    • About EngageMedia
    • The EngageMedia Team
    • Consultancy Services
    • Privacy Policy
  • Resources
    • All Resources
    • Video for Change Impact Toolkit
    • Video Compression – Step-by-Step Handbrake Tutorial
    • Best Practices for Online Subtitling
    • Video Compression Guide
  • Research
  • Projects
  • Jobs
  • Partners
  • Newsletter
  • Support Us
  • Contact