11/08/2026
នេះគឺជាមូលហេតុធំបំផុតមួយដែលនាំឱ្យគណនីត្រូវគេលួច (Hack) នៅកម្ពុជា (និងនៅគ្រប់ទីកន្លែង) — គឺការប្រើលេខសម្ងាត់ខ្សោយ និងងាយស្មានដឹង ៖
ទម្រង់លេខសម្ងាត់ខ្សោយទូទៅដែលមនុស្សចូលចិត្តប្រើ ៖
លេខទូរស័ព្ទធ្វើជាលេខសម្ងាត់ — ឧទាហរណ៍៖ ប្រើលេខ 0977123456 ឬលេខ ៦ ទៅ ៨ ខ្ទង់ចុងក្រោយ។ អ្នកវាយប្រហារ (Attackers) មានលេខទូរស័ព្ទរបស់អ្នករួចជាស្រេចទៅហើយ (ព្រោះជាផ្លូវដែលគេទាក់ទងមកអ្នកលើ Telegram/Facebook ដំបូង) ដូច្នេះការធ្វើបែបនេះ គឺស្មើនឹងការហុចលេខសម្ងាត់ឱ្យគេដោយផ្ទាល់តែម្តង។
ថ្ងៃខែឆ្នាំកំណើត — ទម្រង់ដូចជា 01011995, 1995, 19950101។ ត្រូវគេប្រើច្រើនបំផុតដោយសារជាងាយស្រួលចាំ — ប៉ុន្តែវាក៏ជាព័ត៌មានសាធារណៈជាញឹកញាប់ផងដែរ ដោយមានបង្ហាញនៅលើ Profile Facebook, អត្តសញ្ញាណប័ណ្ណដែលបានចែករំលែកក្នុង Group Telegram ឬអាចស្មានដឹងចេញពីការផុសរូបការ/ខួបកំណើត។
តួលេខរៀបតាមលំដាប់ងាយៗ — 123456, 123456789, 111111, 000000។ ទាំងនេះគឺជាលេខសម្ងាត់ដែលត្រូវគេ Hack បានច្រើនជាងគេបំផុតនៅលើពិភពលោក យោងតាមការសិក្សាលើទិន្នន័យជ្រោះធ្លាយលេខសម្ងាត់ទាំងអស់ ដោយគ្មានការលើកលែង។
ឈ្មោះ + ឆ្នាំ — ឧទាហរណ៍៖ sokha1995, dara2023។ ងាយស្រួលស្មានប្រសិនបើអ្នក Hack ស្គាល់ឈ្មោះបុគ្គលនោះ (ដែលគេដឹងស្រាប់ហើយ ព្រោះគេតម្រង់ទិសដៅលើឈ្មោះ/Profile នោះ) ហើយអាចប៉ាន់ស្មានអាយុ ឬឆ្នាំបញ្ចប់ការសិក្សាចេញពី Facebook។
ឈ្មោះ + លេខទូរស័ព្ទ/ថ្ងៃខែឆ្នាំកំណើត — sokha0977, dara0101។ បញ្ហាដូចគ្នា — ព្រោះផ្នែកទាំងពីរនៃលេខសម្ងាត់សុទ្ធតែជាព័ត៌មានសាធារណៈ។
ទម្រង់ចុចលើក្ដារចុច (Keyboard) — qwerty, asdf1234, 1qaz2wsx។ ងាយស្រួលវាយ និងងាយស្រួលស្មាន។
ប្រើលេខសម្ងាត់ដដែលៗនៅគ្រប់កន្លែង — នេះអាចនិយាយបានថាជាបញ្ហាធំបំផុត។ ប្រសិនបើ Facebook, អ៊ីមែល ឬគេហទំព័រទិញទំនិញណាមួយរបស់នរណាម្នាក់ត្រូវគេទម្លុះទិន្នន័យ (ហើយ Web តូចៗត្រូវគេ Hack ជារឿយៗ) ហើយពួកគេប្រើលេខសម្ងាត់ដដែលនោះលើ Telegram/អ៊ីមែល នោះអ្នក Hack គ្រាន់តែយកលេខសម្ងាត់ដែលលេចធ្លាយនោះទៅសាកល្បងលើគណនីផ្សេងទៀត។ វិធីនេះហៅថា Credential Stuffing ហើយវាពេញនិយមបំផុត។
ហេតុអ្វីបានជាចំណុចនេះសំខាន់ជាពិសេសសម្រាប់បរិបទ Telegram/កម្ពុជា៖
Telegram ខ្លួនឯង មិនត្រូវគេ "Hack" តាមរយៈការស្មានលេខសម្ងាត់នោះទេ (វាប្រើលេខទូរស័ព្ទ + លេខ OTP មិនមែនប្រើតែលេខសម្ងាត់ឡើយ) — ប៉ុន្តែគណនីអ៊ីមែលដែលភ្ជាប់សម្រាប់សង្គ្រោះ (Recovery), Facebook និងកម្មវិធីធនាគារ ច្រើនតែប្រើលេខសម្ងាត់ងាយៗ ហើយនៅពេលអ៊ីមែលរបស់នរណាម្នាក់ត្រូវគេ Hack គេអាចកំណត់ឡើងវិញ (Reset) នូវអ្វីៗគ្រប់យ៉ាងដែលភ្ជាប់ជាមួយអ៊ីមែលនោះ។
លេខសម្ងាត់ 2FA (Two-Step Verification) ដែលអ្នករៀបចំនៅក្នុង Telegram ច្រើនតែជាកន្លែងដែលមនុស្សយក "លេខសម្ងាត់ធម្មតា" ដែលខ្សោយមកប្រើឡើងវិញ — ធ្វើឱ្យបាត់បង់ប្រយោជន៍ និងគោលបំណងនៃការបង្កើត 2FA ទាំងស្រុង។
This is one of the biggest reasons accounts get hacked in Cambodia (and everywhere) — weak, guessable passwords. Here's the breakdown, good for your awareness content:
Common weak password patterns people use:
Phone number as password — e.g. using 0977123456 or the last 6-8 digits. Attackers already have your phone number (that's how they contact you on Telegram/Facebook in the first place), so this is basically handing them the password directly.
Date of birth — formats like 01011995, 1995, 19950101. Extremely common because it's easy to remember — but it's also often public, visible on Facebook profiles, ID cards shared in Telegram groups, or even guessable from a wedding/birthday post.
Simple number sequences — 123456, 123456789, 111111, 000000. These are the #1 most cracked passwords worldwide in every leaked-password study, no exceptions.
Name + year — e.g. sokha1995, dara2023. Easy to guess if the attacker knows the person's name (which they do, since they're targeting them by name/profile) and can estimate age or graduation year from Facebook.
Name + phone/DOB combo — sokha0977, dara0101. Same issue — both halves are often public info.
Keyboard patterns — qwerty, asdf1234, 1qaz2wsx. Easy to type, easy to guess.
Same password reused everywhere — this is arguably the biggest one. If someone's Facebook, email, or a random shopping site gets breached (and small websites get breached constantly), and they used the same password on Telegram/email, the attacker just tries that leaked password on other accounts. This is called credential stuffing and it's extremely common.
Why this matters specifically for Telegram/Cambodia context:
Telegram itself doesn't get "hacked" via password guessing (it uses phone + OTP, not just password) — but email accounts tied to recovery, Facebook, and banking apps often do use simple passwords, and once someone's email is hacked, they can reset almost everything else linked to it.
The 2FA password (Two-Step Verification) you set up in Telegram is often where people reuse their weak "usual password" — defeating the whole purpose of having 2FA.