Thailand considers mandatory MFA after 60 million credential records appear on dark web

0

Thailand’s Ministry of Digital Economy and Society was preparing to seek Cabinet backing to make multi-factor authentication (MFA) compulsory across government systems, after about 60 million credential records containing usernames and passwords were reported leaked on dark-web markets.

The development was highlighted in comments circulated by McGallen & Bolden, attributing the figures to the ministry and framing the incident as part of a wider shift toward “identity” controls as a core element of cyber defence.

In a statement provided to media, Takanori Nishiyama, senior vice president for APAC at Keeper Security, cited Verizon’s 2026 Data Breach Investigations Report, saying credential abuse was the initial access vector in 25% of APAC breaches, and present across 39% of full breach chains globally.

“Cybercriminals increasingly log in rather than break in: Verizon’s 2026 Data Breach Investigations Report found that credential abuse was the initial access vector in 25% of APAC breaches, second only to vulnerability exploitation at 42%, and that credential abuse appears across 39% of full breach chains globally. Thailand’s Digital Economy and Society Ministry reported that about 60 million additional Thai-linked credential records accumulated on dark-web markets over the past year. Criminals bought stolen usernames and passwords, then simply logged in through connected Application Programming Interfaces (APIs) to extract data.

The underlying systems were not directly breached. That distinction is the point: when valid credentials open the door, perimeter defences and even fully patched systems offer little protection. Data tied to senior officials and more than 500,000 citizen records have surfaced across at least 20 state agencies, showing how quickly a credential problem becomes a national one.

The conditions behind this incident are not unique to Thailand. Japanese government agencies and enterprises hold similarly vast stores of citizen and customer data across interconnected systems, and Japan has seen its own credential-driven incidents in recent years. Japan’s policy direction, including the Active Cyber Defense Law and the government’s broader shift toward zero-trust principles, reflects the same recognition driving Thailand’s response: static passwords alone can no longer protect systems of national importance.

Security teams should treat identity as the primary control plane. Enforcing multi-factor authentication everywhere, retiring dormant and orphaned accounts and applying least-privilege access ensures a single stolen credential cannot move laterally. Privileged Access Management helps organizations remove standing privileges, grant just-in-time access and monitor privileged sessions in real time. Thailand’s mandated password resets and system cleansing are sound first steps. Organisations should not wait for a breach of this scale to act. Audit who and what can access each system now, and make that review continuous.”

Share.

Comments are closed.

Visit Us On TwitterVisit Us On FacebookVisit Us On LinkedinVisit Us On Youtube