Thailand's government discovered over 200 million leaked login credentials affecting 30,000 state systems and announced emergency measures including forced password resets and multi-factor authentication across all agencies within 15 days.
On August 10, the Digital Economy and Society Ministry held a press conference to announce enhanced cybersecurity measures for government agencies. Digital Economy Minister Chaiyachok Chidchob revealed that the ministry will present cybersecurity safeguard measures to the Cabinet on August 11, emphasizing the adoption of multi-factor authentication (MFA) and emergency protocols to force immediate password resets across all government systems.
Chaidchob disclosed that globally there are approximately 50 billion accumulated leaked login credentials, while Thailand alone has over 200 million compromised login records. The breaches involve approximately 30,000 government systems and more than 35,000 private sector systems. These credentials have been leaked over time and accumulated in various databases, including the Dark Web, though not all associated accounts are necessarily still active.
The minister explained that recent data breaches were not caused by direct cybersecurity system hacks, but rather by credential leaks where passwords and login information were stolen, sold on the Dark Web, and then used to access systems through normal channels and APIs. Rather than simply patching vulnerabilities, the solution requires breaking the cycle of leaked credentials through password changes and enhanced authentication methods.
Chaidchob noted that password resets are only a short-term measure. The government's immediate action is a forced reset of all passwords across government systems so that old compromised credentials become unusable. The ministry will not just check accounts with leaked passwords but will comprehensively review all approximately 30,000 government systems—whether active, discontinued, externally accessible, or hidden—and aims to complete system cleansing and deactivate unnecessary systems within 15 days.
Regarding MFA implementation, the minister emphasized that it should not be limited to just two factors but tailored to the risk profile of each system. The ministry will convene all ministries and approximately 300 department-level agencies to comprehensively review system architecture, access channels, and security measures. Cybersecurity and digitalization will be incorporated as key performance indicators and linked to budgeting.
While most of the 200 million compromised credentials accumulated over several years, particularly during the COVID-19 period, the government cannot guarantee that future breaches will not occur. However, it is committed to achieving maximum system security through improved risk management, MFA deployment, deactivation of unnecessary systems, and long-term elevation of cybersecurity standards.