The exposure of an AIS database online allowed the leak of Internet records of billions of Thai users.

largest network , AIS, took offline a database that allowed anyone to see the online behavior of billions of users.
Security researcher Justin Paine said he found the database online , which contained DNS queries and Netflow data , without a password. If someone gained access to this database, they could “get a picture” of a user’s (or their entire family’s) online activities in real time.
Paine notified AIS about the open database on May 13. However, he did not receive a response from the company, so after a week he notified Thailand's National Emergency Response Team, known as ThaiCERT, which contacted AIS.

Shortly after, the database was no longer accessible.
AIS spokesman Sudaporn Watcharanisakorn confirmed the database leak and said it belonged to the company, while apologizing for the security lapse.
"We can confirm that a small amount of non-personal, non-critical information was exposed for a limited time onlinein May during a planned test," the AIS spokesperson said.
See also: 200 million Twitter data leaks online
“All of the data was related to internet usage patterns and did not contain any personal information that could be used to identify any customer,” it said. “We apologize.”
However, regardless of the spokesperson’s statement, some of the leaked data does provide some information about users . DNS queries are a byproduct of Internet usage. Every time you visit a site, your browser converts a web address into an IP address, which tells the browser where the website “lives” on the Internet. While DNS queries don’t carry private messages, emails, or sensitive data like passwords , they can determine which sites you access and which applications you use.
This could be a big problem for “high-risk individuals,” such as journalists and activists, whose Internet records could be used to identify their sources.
DNS queries can be used to obtain information about users' online activity.
Researcher Paine showed that anyone who had access to the database could learn a lot about a home with an Internet connection, such as the types of devices, antivirus programs and browsers that users use, as well as the sites they visit and the social media apps they have.
However, in households or offices, many people share an Internet connection, so it is difficult to associate online activity with a specific person.
Finally, companies find DNS data for serving targeted ads.
