The conclusions of the NHRC’s report are also reflected in the Administrative Court’s ruling in October 2025. The case was filed by Sarinee Achavanuntakul, Winyu Wongsurawat, and Yingcheep Atchanont. Sarinee is an independent academic and a regular critic of government policies; Yingcheep is the director of iLaw; and Winyu is the executive director of SpokeDark.tv, an independent media outlet. All three frequently discuss political issues on their social media channels. The case was filed in 2021 after they found themselves targeted by cyber trolls allegedly linked to military-affiliated IO operations459. Although the Administrative Court dismissed their lawsuit, it found that the documents submitted by the plaintiffs, which instructed the IO on its operations, were authentic460. The court did not deny the existence of the operations but ruled that actions taken by accounts believed to be IO—such as liking, sharing, or commenting—could reflect the personal opinions of the individuals behind those accounts461. As iLaw examined the URLs provided in the documents used during the March 2025 parliamentary debate, many posts from these URLs, allegedly part of the IO, were found to be targeting the three individuals462. Beyond these matters, the documents presented during the parliamentary debate also provide insight into the military’s efforts to produce AI-generated content. They further highlight a digital security dimension, noting that the military attempted to access targeted social media accounts using brute-force attacks. A brute-force attack is a method used by attackers to gain unauthorized access to systems by systematically trying all possible combinations of passwords or encryption keys until the correct one is found. For example, the military reportedly described its attempts to gain access to Sarinee Achavanuntakul’s social media account, but did not succeed. The documents also describe tactics such as mass-reporting accounts or posts to prompt suspensions by social media platforms, as well as phishing and spamming campaigns. Denial-of-service (DoS) attacks and the creation of fake Wi-Fi access points are also highlighted in the documents as techniques the military is learning to deploy against its targets. A DoS attack is a cyberattack designed to make a website, network, or device unavailable to legitimate users by overwhelming it with excessive traffic or malicious requests. This creates a virtual traffic jam that exhausts system resources such as “Central Administrative Court Dismisses Lawsuit by Sarinee, Yingcheep, and John Winyu Against the Royal Thai Army for Using “IO” to Attack Dissenters.” BBC News Thai, 30 Oct. 2025, www.bbc.com/thai/ articles/cly91qnv9zjo. 460. “Judges Believe the IO Documents Are Authentic, but Notes That Those IO Accounts May Have Posted Personal Opinions on Social Media.” iLaw, 15 Oct. 2025, www.ilaw.or.th/articles/55512. 461. “Administrative Court Dismisses IO Case, Finding the Order Exists but Determining Soldiers Not at Fault for Possibly Only Expressing Personal Opinions” iLaw, 30 Oct. 2025, www.ilaw.or.th/articles/55744. 462. “IO – Part Three: iLaw Remains a Constant Target, Even Wrongly Link to Unrelated Matters.” iLaw, 28 Aug. 2025, www.ilaw.or.th/articles/54191. 459. 91

Select target paragraph3