Thailand Plans Multi-Factor Authentication Push to Combat Data Leaks
Thailand's government will mandate multi-factor authentication and force password resets across 30,000 government systems after 200 million Thai login credentials were found in global data breaches, with implementation targeted within 15 da
Digital Economy and Society Minister Chaiyachanok Chidchob announced on August 10 that the DE will present cybersecurity protection measures to the cabinet on August 11, emphasizing the rollout of multi-factor authentication (MFA) paired with urgent mandatory password resets across all government systems. According to the ministry's data compilation, approximately 200 million login credentials linked to Thailand have been found among 50 billion compromised credentials globally, with around 30,000 government systems and over 35,000 private sector systems affected. These credentials are accumulated in various databases including the Dark Web, though not all accounts remain active.
Chaidchob explained that recent data leaks resulted not from direct system hacking but from credential leaks—where usernames and passwords were stolen, sold on the Dark Web, and then used to access systems through normal channels and APIs. The solution requires not just fixing vulnerabilities but breaking the cycle of leaked login data through password changes and enhanced authentication.
"Password resets are only a short-term measure to buy time, as new passwords can still be stolen if users are tricked into clicking unsafe links or entering data in compromised channels," Chaidchob stated. "The immediate action needed is a Force Reset—mandatory password changes across all government systems so old passwords found in leaked databases become useless."
The ministry will review all approximately 30,000 government systems—both active and inactive, externally accessible and backend systems—setting a 15-day target for system cleansing and decommissioning unnecessary platforms. MFA implementation will be tailored to each system's risk level rather than limited to two factors. The DE will also convene over 300 ministries and department-level agencies to comprehensively audit their systems, structure, access channels, and security measures, integrating cybersecurity and digitalization into performance indicators and budgets.
While most of Thailand's 200 million compromised credentials accumulated over years, particularly during the COVID-19 period, the government acknowledged it cannot guarantee future leaks but will accelerate system security through risk management, MFA deployment, system decommissioning, and long-term cybersecurity standards upgrades.