PKF Thailand Transparency Report 2025

PKF Thailand is pleased to present our inaugural transparency report for the year ended 30 June 2025. It provides an overview of PKF Thailand’s operations and gives insight on the ownership and governance of our firm, and our approach to maintaining high quality standards in our audit and other services.

Outsourcing Without Oversight: PDPA Penalties Hit Healthcare Sector

On August 1, 2025, Thailand’s Personal Data Protection Committee (PDPC) issued a formal statement regarding a serious data breach involving a prominent private hospital. The incident has sparked widespread attention across social media and raised concerns about data governance in the healthcare sector. Incident Overview The hospital, acting as the Data Controller, had outsourced the […]

How attackers are still phishing “phishing-resistant” authentication

🔐 Overview Despite the rise in phishing‑resistant authentication methods such as FIDO2-based passkeys, WebAuthn, Windows Hello, and physical security keys attackers continue to successfully bypass them using more sophisticated phishing techniques. 🧪 Attack Techniques Used 1. Downgrade Attacks 2. Device‑Code Phishing 3. Consent Phishing (OAuth Abuse) ⚖️ Why These Methods Still Work ✅ Mitigation Strategies […]

Thailand’s Employee Welfare Fund 2025: What Employers Need to Know

Starting October 1, 2025, Thailand will officially launch the Employee Welfare Fund (EWF) — a major
step forward in protecting workers’ financial well-being. After years of delay, this mandatory fund, grounded in the Labour Protection Act B.E. 2541 (1998), is now set in motion following a royal decree and regulations passed in late 2024

16 billion passwords exposed in record-breaking data breach

The massive excitement around Artificial Intelligence (AI) tools has become a goldmine for cybercriminals. They’re heavily using this buzz to trick people into downloading dangerous ransomware and malware. This isn’t just a tactic for highly advanced hackers anymore; even smaller, lesser-known groups are now effectively using this strategy. These malicious actors, including ransomware gangs like […]