Cabinet Orders 300 Agencies to Reset Passwords, Audit 30,000 Systems
Thailand's Cabinet ordered 300 government agencies to reset passwords and audit 30,000 computer systems within 15 days to prevent data breaches, while mandating multi-factor authentication across all public sector infrastructure.
On August 11, 2025, government spokesman Ratchada Thanadirek announced Cabinet approval of measures to prevent personal data breaches resulting from compromised user account credentials. The Cabinet endorsed the use of multi-factor authentication (MFA)—such as Digital Identity (ThaID) or other secure verification methods—as recommended by the National Cybersecurity Committee, to strengthen personal data protection and systematically reduce cyber threats across the public sector.
The Cabinet approved three specific measures: first, a forced password reset requiring civil servants and officials across more than 300 government agencies to change passwords immediately, preventing malicious actors from exploiting leaked databases. Second, a system cleansing initiative mandating all ministries and 300 agencies to audit over 30,000 information systems within 15 days, permanently deactivating obsolete or abandoned systems' backend access, as many agencies had closed front-end access while leaving backend systems vulnerable. Third, the government will implement multi-factor authentication across all public sector systems. The National Cybersecurity Committee has been authorized to coordinate with both public and private sector organizations to execute these directives under the Cybersecurity Act of 2019.