The conclusions of the NHRC’s report are also reflected in the Administrative Court’s ruling
in October 2025. The case was filed by Sarinee Achavanuntakul, Winyu Wongsurawat,
and Yingcheep Atchanont. Sarinee is an independent academic and a regular critic of
government policies; Yingcheep is the director of iLaw; and Winyu is the executive director
of SpokeDark.tv, an independent media outlet. All three frequently discuss political issues
on their social media channels. The case was filed in 2021 after they found themselves
targeted by cyber trolls allegedly linked to military-affiliated IO operations459.
Although the Administrative Court dismissed their lawsuit, it found that the documents
submitted by the plaintiffs, which instructed the IO on its operations, were authentic460.
The court did not deny the existence of the operations but ruled that actions taken by
accounts believed to be IO—such as liking, sharing, or commenting—could reflect
the personal opinions of the individuals behind those accounts461.
As iLaw examined the URLs provided in the documents used during the March 2025
parliamentary debate, many posts from these URLs, allegedly part of the IO, were found to
be targeting the three individuals462.
Beyond these matters, the documents presented during the parliamentary debate also
provide insight into the military’s efforts to produce AI-generated content. They further
highlight a digital security dimension, noting that the military attempted to access
targeted social media accounts using brute-force attacks. A brute-force attack is a method
used by attackers to gain unauthorized access to systems by systematically trying all
possible combinations of passwords or encryption keys until the correct one is found.
For example, the military reportedly described its attempts to gain access to Sarinee
Achavanuntakul’s social media account, but did not succeed. The documents also
describe tactics such as mass-reporting accounts or posts to prompt suspensions by
social media platforms, as well as phishing and spamming campaigns.
Denial-of-service (DoS) attacks and the creation of fake Wi-Fi access points are also
highlighted in the documents as techniques the military is learning to deploy against its
targets. A DoS attack is a cyberattack designed to make a website, network, or device
unavailable to legitimate users by overwhelming it with excessive traffic or malicious
requests. This creates a virtual traffic jam that exhausts system resources such as
“Central Administrative Court Dismisses Lawsuit by Sarinee, Yingcheep, and John Winyu Against the
Royal Thai Army for Using “IO” to Attack Dissenters.” BBC News Thai, 30 Oct. 2025, www.bbc.com/thai/
articles/cly91qnv9zjo.
460.
“Judges Believe the IO Documents Are Authentic, but Notes That Those IO Accounts May Have Posted
Personal Opinions on Social Media.” iLaw, 15 Oct. 2025, www.ilaw.or.th/articles/55512.
461.
“Administrative Court Dismisses IO Case, Finding the Order Exists but Determining Soldiers Not at Fault
for Possibly Only Expressing Personal Opinions” iLaw, 30 Oct. 2025, www.ilaw.or.th/articles/55744.
462.
“IO – Part Three: iLaw Remains a Constant Target, Even Wrongly Link to Unrelated Matters.” iLaw, 28 Aug.
2025, www.ilaw.or.th/articles/54191.
459.
91